3.8

CVSS3.1

CVE-2026-22014 -

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User…

📅 Published: April 21, 2026, 8:35 p.m. 🔄 Last Modified: April 23, 2026, 3:01 p.m.

7.6

CVSS3.1

CVE-2026-22011 - High‑Privilege Remote Takeover via HTTP in Oracle Applications DBA

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Suc…

📅 Published: April 21, 2026, 8:35 p.m. 🔄 Last Modified: April 23, 2026, 3:02 p.m.

7.5

CVSS3.1

CVE-2026-22010 - Unauthenticated HTTP Remote Confidentiality Exposure in Oracle Financial Services Analytical Applic…

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker wi…

📅 Published: April 21, 2026, 8:35 p.m. 🔄 Last Modified: April 23, 2026, 3:02 p.m.

5.4

CVSS3.1

CVE-2026-22006 - PeopleSoft Employee Snapshot Vulnerability Allows Unauthorized Data Modification

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterpri…

📅 Published: April 21, 2026, 8:35 p.m. 🔄 Last Modified: April 23, 2026, 3:03 p.m.

6

CVSS3.1

CVE-2026-22003 - Local Privileged Code Execution and Denial of Service in Oracle Java SE and GraalVM

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u481 and 8u481-b50; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows low privileged…

📅 Published: April 21, 2026, 8:35 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

5.3

CVSS3.1

CVE-2026-21999 - Unauthenticated XML Database Access via HTTPS in Oracle Database Server

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database. Successful attacks require human interaction…

📅 Published: April 21, 2026, 8:34 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

8.5

CVSS3.1

CVE-2026-21997 - Remote Unauthorized Data Modification and Read in Oracle Life Sciences Empirica Signal via Low-Priv…

Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Li…

📅 Published: April 21, 2026, 8:34 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

5.3

CVSS4.0

CVE-2026-6796 - Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file

A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword causes cleartext st…

📅 Published: April 21, 2026, 8:30 p.m. 🔄 Last Modified: April 22, 2026, 5:30 a.m.

6.5

CVSS3.1

CVE-2026-40910 - frp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for access control

frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. In proxy-style requests, the routing logic uses the username from Proxy-Authorization to select the routeByHTTPUser backen…

📅 Published: April 21, 2026, 8:09 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

10

CVSS3.1

CVE-2026-40906 - Electric: SQL Injection via ORDER BY Parameter in Shape API

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted OR…

📅 Published: April 21, 2026, 8:05 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.
Total resulsts: 346271
Page 67 of 34,628
« previous page » next page
Filters