| CVE-2026-71143 | 7.4 | — | — | — | oracle / communications unified inventory management | Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (componen | 53d ago |
| CVE-2026-71009 | 7.4 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 53d ago |
| CVE-2026-70898 | 7.4 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 53d ago |
| CVE-2026-70823 | 7.4 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 53d ago |
| CVE-2026-70790 | 7.4 | — | — | — | oracle / telecommunications billing integrator | Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: I | 53d ago |
| CVE-2026-70783 | 7.4 | — | — | — | oracle / service contracts | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). | 53d ago |
| CVE-2026-70779 | 7.4 | — | — | — | oracle / isupplier portal | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). | 53d ago |
| CVE-2026-70734 | 7.4 | — | — | — | oracle / autonomous health framework | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). | 53d ago |
| CVE-2026-70699 | 7.4 | — | — | — | oracle / payments | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). | 53d ago |
| CVE-2026-70672 | 7.4 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 53d ago |
| CVE-2026-62538 | 7.4 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 53d ago |
| CVE-2026-62492 | 7.4 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Secur | 53d ago |
| CVE-2026-60933 | 7.4 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60915 | 7.4 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 53d ago |
| CVE-2026-60856 | 7.4 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packag | 53d ago |
| CVE-2026-60820 | 7.4 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). | 53d ago |
| CVE-2026-60803 | 7.4 | — | — | — | oracle / siebel apps - marketing | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). | 53d ago |
| CVE-2026-60797 | 7.4 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). | 53d ago |
| CVE-2026-60792 | 7.4 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). | 53d ago |
| CVE-2026-60766 | 7.4 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). | 53d ago |
| CVE-2026-60759 | 7.4 | — | — | — | — | Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal | 53d ago |
| CVE-2026-70666 | 7.4 | — | — | — | — | Lemur manages TLS certificate creation. | 53d ago |
| CVE-2026-50577 | 7.4 | — | — | — | — | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's elec | 53d ago |
| CVE-2026-75912 | 7.4 | — | — | — | — | CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows att | 53d ago |
| CVE-2026-66635 | 7.4 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | 53d ago |
| CVE-2026-59825 | 7.4 | — | — | — | — | Mastodon is a free, open-source social network server based on ActivityPub. | 53d ago |
| CVE-2026-18534 | 7.4 | — | — | — | — | ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowi | 53d ago |
| CVE-2026-19982 | 7.4 | — | — | — | — | A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. | 54d ago |
| CVE-2026-19981 | 7.4 | — | — | — | — | A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, | 54d ago |
| CVE-2026-19980 | 7.4 | — | — | — | — | A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5 | 54d ago |
| CVE-2026-19963 | 7.4 | — | — | — | — | A vulnerability has been found in Edimax EW-7478APC 1.04. | 54d ago |
| CVE-2026-19962 | 7.4 | — | — | — | — | A flaw has been found in Edimax EW-7478APC 1.04. | 54d ago |
| CVE-2026-19960 | 7.4 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7478APC 1.04. | 54d ago |
| CVE-2026-74356 | 7.4 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost: fix vhost_get_avail_idx for a non empty | 56d ago |
| CVE-2026-73655 | 7.4 | — | — | — | — | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. | 58d ago |
| CVE-2026-70452 | 7.4 | — | — | — | — | rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumven | 58d ago |
| CVE-2026-53793 | 7.4 | — | — | — | — | rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the inten | 58d ago |
| CVE-2026-49857 | 7.4 | — | — | — | — | auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. | 58d ago |
| CVE-2026-28189 | 7.4 | — | — | — | — | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | 58d ago |
| CVE-2026-73495 | 7.4 | — | — | — | — | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. | 58d ago |
| CVE-2026-67579 | 7.4 | — | — | — | ash-hq / ash framework | Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a | 59d ago |
| CVE-2026-11923 | 7.4 | — | — | — | ibm / security verify access | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify | 59d ago |
| CVE-2026-48551 | 7.4 | — | — | — | — | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via | 59d ago |
| CVE-2026-67558 | 7.4 | — | — | — | — | The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring mat | 59d ago |
| CVE-2026-73086 | 7.4 | — | — | — | — | nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. | 60d ago |
| CVE-2026-58612 | 7.4 | — | — | — | microsoft / powershell | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose inform | 60d ago |
| CVE-2026-22887 | 7.4 | — | — | — | intel / proset\/wireless wifi | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may | 60d ago |
| CVE-2026-20886 | 7.4 | — | — | — | intel / proset\/wireless wifi | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may | 60d ago |
| CVE-2026-20878 | 7.4 | — | — | — | intel / proset\/wireless wifi | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers | 60d ago |
| CVE-2026-20795 | 7.4 | — | — | — | intel / proset\/wireless wifi | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Dri | 60d ago |
| CVE-2026-20787 | 7.4 | — | — | — | intel / proset\/wireless wifi | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers | 60d ago |
| CVE-2026-20745 | 7.4 | — | — | — | intel / proset\/wireless wifi | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may | 60d ago |
| CVE-2026-20741 | 7.4 | — | — | — | intel / proset\/wireless wifi | Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a | 60d ago |
| CVE-2026-20739 | 7.4 | — | — | — | intel / proset\/wireless wifi | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Driver | 60d ago |
| CVE-2026-50237 | 7.4 | — | — | — | — | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. | 60d ago |
| CVE-2026-50236 | 7.4 | — | — | — | — | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. | 60d ago |
| CVE-2026-15563 | 7.4 | — | — | — | — | A flaw was found in EAP's IIOP. | 60d ago |
| CVE-2026-15554 | 7.4 | — | — | — | — | the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret au | 60d ago |
| CVE-2026-72584 | 7.4 | — | — | — | — | A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote | 61d ago |
| CVE-2026-48084 | 7.4 | — | — | — | — | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. | 64d ago |