CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-83274
5.5 MEDIUM

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily …

Sep 15, 2026
CVE-2026-83251
6.5 MEDIUM

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is …

Sep 15, 2026
CVE-2026-83250
6.5 MEDIUM

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is …

Sep 15, 2026
CVE-2026-83200
6.5 MEDIUM

Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability …

Sep 15, 2026
CVE-2026-83198
5.4 MEDIUM

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-83175
6.5 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-83140
6.5 MEDIUM

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-83109
5.3 MEDIUM

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily …

Sep 15, 2026
CVE-2026-83097
6.5 MEDIUM

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily …

Sep 15, 2026
CVE-2026-83077
6.4 MEDIUM

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable …

Sep 15, 2026
CVE-2026-83076
6.8 MEDIUM

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability …

Sep 15, 2026
CVE-2026-81925
6.1 MEDIUM

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary …

Sep 15, 2026
CVE-2026-76796
4.0 MEDIUM

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path …

Sep 15, 2026
CVE-2026-76707
4.3 MEDIUM

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an …

Sep 15, 2026
CVE-2026-76706
5.3 MEDIUM

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could …

Sep 15, 2026
CVE-2026-76705
5.5 MEDIUM

A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin …

Sep 15, 2026
CVE-2026-76704
5.5 MEDIUM

A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a …

Sep 15, 2026
CVE-2026-76703
5.5 MEDIUM

A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access …

Sep 15, 2026
CVE-2026-76702
5.8 MEDIUM

A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could …

Sep 15, 2026
CVE-2026-76701
5.9 MEDIUM

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could …

Sep 15, 2026
CVE-2026-76700
5.9 MEDIUM

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt …

Sep 15, 2026
CVE-2026-76699
6.4 MEDIUM

A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated …

Sep 15, 2026
CVE-2026-76698
6.5 MEDIUM

A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could …

Sep 15, 2026
CVE-2026-76697
6.5 MEDIUM

A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive …

Sep 15, 2026
CVE-2026-76696
6.5 MEDIUM

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow …

Sep 15, 2026
CVE-2026-76695
6.5 MEDIUM

Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially …

Sep 15, 2026
CVE-2026-76694
6.6 MEDIUM

A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with …

Sep 15, 2026
CVE-2026-73965
6.8 MEDIUM

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability …

Sep 15, 2026
CVE-2026-70755
6.5 MEDIUM

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable …

Sep 15, 2026
CVE-2026-69215
6.8 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 …

Sep 15, 2026
CVE-2026-69206
5.9 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count …

Sep 15, 2026
CVE-2026-62597
6.5 MEDIUM

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. …

Sep 15, 2026
CVE-2026-51133
6.1 MEDIUM

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in …

Sep 15, 2026
CVE-2026-18422
6.5 MEDIUM

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action …

Sep 15, 2026
CVE-2026-90971
6.5 MEDIUM

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials …

Sep 15, 2026
CVE-2026-90969
6.5 MEDIUM

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain …

Sep 15, 2026
CVE-2026-84850
4.8 MEDIUM

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to …

Sep 15, 2026
CVE-2026-81924
6.5 MEDIUM

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created …

Sep 15, 2026
CVE-2026-81921
5.4 MEDIUM

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid …

Sep 15, 2026
CVE-2026-81920
4.3 MEDIUM

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word …

Sep 15, 2026
CVE-2026-81919
4.3 MEDIUM

Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization …

Sep 15, 2026
CVE-2026-79409
6.5 MEDIUM

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

Sep 15, 2026
CVE-2026-73467
6.3 MEDIUM

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

Sep 15, 2026
CVE-2026-73466
6.3 MEDIUM

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard …

Sep 15, 2026
CVE-2026-73465
6.3 MEDIUM

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized …

Sep 15, 2026
CVE-2026-73451
4.8 MEDIUM

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting …

Sep 15, 2026
CVE-2026-69216
5.4 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or …

Sep 15, 2026
CVE-2026-69214
6.8 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking …

Sep 15, 2026
CVE-2026-69212
5.9 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a …

Sep 15, 2026
CVE-2026-69211
4.8 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.