5.4

CVSS3.1

CVE-2026-21934 - Unauthorized Data Manipulation via Push Notifications in PeopleSoft Enterprise PeopleTools

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Push Notifications). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft …

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

5.4

CVSS3.1

CVE-2026-21931 -

Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App). Supported versions that are affected are 23.2.0, 23.2.1, 24.1.0, 24.2.0 and 24.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compr…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

2.3

CVSS3.1

CVE-2026-21930 - Unauthorized Data Modification via Privileged Account in Oracle ZFS Storage Appliance Kit 8.8

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit execute…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

5.3

CVSS3.1

CVE-2026-21928 - Unauthorized Data Disclosure via Network in Oracle Solaris 11 Kernel

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Solaris. Successful attacks of this vulnerability can…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

5.8

CVSS3.1

CVE-2026-21927 - Privilege‑Based Data Modification in Oracle Solaris Driver

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successfu…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 7:15 p.m.

7.5

CVSS3.1

CVE-2026-21926 -

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-25.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Siebel CRM Deployment. Success…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

5.4

CVSS3.1

CVE-2026-21924 - Low‑Privilege Data Manipulation via HTTP in Oracle Utilities Application Framework

Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General). Supported versions that are affected are 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and 25.10. Easily exploitable vulnerability allows low privileged attacke…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

6.5

CVSS3.1

CVE-2026-21923 - Unauthenticated HTTP Data Modification and Disclosure in Oracle Life Sciences Central Designer

Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Li…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

4.2

CVSS3.1

CVE-2026-21922 - Compromise of Oracle Planning and Budgeting Cloud Service via privileged EPM Agent vulnerability

Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budge…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 3:45 p.m.

6

CVSS4.0

CVE-2026-0672 - Header injection in http.cookies.Morsel

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

📅 Published: Jan. 20, 2026, 9:52 p.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.
Total resulsts: 346103
Page 1744 of 34,611
« previous page » next page
Filters