Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29232
Total
2268
Critical
8711
High
9096
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-22017 | MEDIUM | 6.5 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability … | Apr 21, 2026 |
| CVE-2026-22016 | HIGH | 7.5 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are … | Apr 21, 2026 |
| CVE-2026-22015 | MEDIUM | 4.3 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable … | Apr 21, 2026 |
| CVE-2026-22014 | LOW | 3.8 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable … | Apr 21, 2026 |
| CVE-2026-22013 | MEDIUM | 5.3 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are … | Apr 21, 2026 |
| CVE-2026-22011 | HIGH | 7.6 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows … | Apr 21, 2026 |
| CVE-2026-22010 | HIGH | 7.5 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 … | Apr 21, 2026 |
| CVE-2026-22009 | MEDIUM | 6.5 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability … | Apr 21, 2026 |
| CVE-2026-22008 | LOW | 3.7 | Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker … | Apr 21, 2026 |
| CVE-2026-22007 | LOW | 2.9 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are … | Apr 21, 2026 |
| CVE-2026-22006 | MEDIUM | 5.4 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable … | Apr 21, 2026 |
| CVE-2026-22005 | MEDIUM | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability … | Apr 21, 2026 |
| CVE-2026-22004 | MEDIUM | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows … | Apr 21, 2026 |
| CVE-2026-22003 | MEDIUM | 6.0 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java … | Apr 21, 2026 |
| CVE-2026-22002 | MEDIUM | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability … | Apr 21, 2026 |
| CVE-2026-22001 | LOW | 2.7 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable … | Apr 21, 2026 |
| CVE-2026-21999 | MEDIUM | 5.3 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with … | Apr 21, 2026 |
| CVE-2026-21998 | MEDIUM | 4.9 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability … | Apr 21, 2026 |
| CVE-2026-21997 | HIGH | 8.5 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily … | Apr 21, 2026 |
| CVE-2025-70420 | HIGH | 8.8 | A SQL injection vulnerability exists in Genesys Latitude v25.1.0.420 that allows an authenticated attacker to execute arbitrary SQL queries against the backend database. The vulnerability … | Apr 21, 2026 |
| CVE-2026-6819 | HIGH | 8.8 | HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. … | Apr 21, 2026 |
| CVE-2026-41320 | MEDIUM | 6.5 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint … | Apr 21, 2026 |
| CVE-2026-40909 | HIGH | 8.7 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating … | Apr 21, 2026 |
| CVE-2026-40908 | MEDIUM | 5.3 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and … | Apr 21, 2026 |
| CVE-2026-40907 | MEDIUM | 6.5 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that … | Apr 21, 2026 |