Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57048
Total
4535
Critical
16933
High
16775
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71047 | HIGH | 8.8 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability … | Sep 15, 2026 |
| CVE-2026-70915 | HIGH | 8.8 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability … | Sep 15, 2026 |
| CVE-2026-70913 | CRITICAL | 9.8 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability … | Sep 15, 2026 |
| CVE-2026-70757 | CRITICAL | 9.8 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily … | Sep 15, 2026 |
| CVE-2026-70756 | CRITICAL | 9.8 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily … | Sep 15, 2026 |
| CVE-2026-70755 | MEDIUM | 6.5 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable … | Sep 15, 2026 |
| CVE-2026-70748 | CRITICAL | 9.8 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily … | Sep 15, 2026 |
| CVE-2026-69218 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection … | Sep 15, 2026 |
| CVE-2026-69217 | HIGH | 8.7 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last … | Sep 15, 2026 |
| CVE-2026-69215 | MEDIUM | 6.8 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 … | Sep 15, 2026 |
| CVE-2026-69210 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit … | Sep 15, 2026 |
| CVE-2026-69206 | MEDIUM | 5.9 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count … | Sep 15, 2026 |
| CVE-2026-69205 | HIGH | 8.7 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and … | Sep 15, 2026 |
| CVE-2026-69203 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS … | Sep 15, 2026 |
| CVE-2026-69202 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the … | Sep 15, 2026 |
| CVE-2026-62597 | MEDIUM | 6.5 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. … | Sep 15, 2026 |
| CVE-2026-61544 | UNKNOWN | — | libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a … | Sep 15, 2026 |
| CVE-2026-51134 | UNKNOWN | — | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml. | Sep 15, 2026 |
| CVE-2026-51133 | UNKNOWN | — | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in … | Sep 15, 2026 |
| CVE-2026-32599 | UNKNOWN | — | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of … | Sep 15, 2026 |
| CVE-2026-18425 | UNKNOWN | — | Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit … | Sep 15, 2026 |
| CVE-2026-18424 | UNKNOWN | — | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple … | Sep 15, 2026 |
| CVE-2026-18423 | UNKNOWN | — | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An … | Sep 15, 2026 |
| CVE-2026-18422 | UNKNOWN | — | Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action … | Sep 15, 2026 |
| CVE-2026-13327 | UNKNOWN | — | Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials … | Sep 15, 2026 |