2026-07-22
2026-07-22 23:16Z
HIGH

CVE-2026-60371 — Vulnerability: Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60371

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. While the vulnerability is in Ora CVSSv3.1 8.0 (HIGH)

VNDVulnerabilityTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-22
2026-07-22 23:16Z
CRIT

CVE-2026-60369 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-22
2026-07-22 23:16Z
HIGH

CVE-2026-60368 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60368

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confide CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 23:16Z
CRIT

CVE-2026-60367 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confid CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-22
2026-07-22 23:16Z
CRIT

CVE-2026-60366 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). CVSSv3.1 10.0 (CRITICAL)

VNDVulnerabilityTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-22
2026-07-22 21:18Z
CRIT

CVE-2026-64798 — Joomla: Extension - regularlabs.com - Insecure login URL keys in IP login extension -

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64798

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 338VNDJoomlaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-22
2026-07-22 21:18Z
CRIT

CVE-2026-64796 — Joomla: Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64796

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 284VNDJoomlaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-22
2026-07-22 21:18Z
CRIT

CVE-2026-64793 — Joomla: Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64793

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 284VNDJoomlaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-22
2026-07-22 21:18Z
HIGH

CVE-2026-64791 — Joomla: Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64791

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions. CVSSv3.1 8.8 (HIGH) · EPSS 1th percentile

CWECWE 352CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:18Z
HIGH

CVE-2026-63685 — Joomla: Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63685

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise. CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:18Z
HIGH

CVE-2026-63684 — Joomla: Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63684

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items. CVSSv3.1 8.8 (HIGH) · EPSS 1th percentile

CWECWE 352CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:18Z
HIGH

CVE-2026-63280 — Joomla: Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63280

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions. CVSSv3.1 8.8 (HIGH) · EPSS 1th percentile

CWECWE 352CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:18Z
HIGH

CVE-2026-63265 — Joomla: Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63265

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization. CVSSv3.1 8.0 (HIGH) · EPSS 1th percentile

CWECWE 352CWECWE 284VNDJoomlaTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-22
2026-07-22 21:17Z
HIGH

CVE-2025-50330 — ZipGenius: An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-50330

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe. CVSSv3.1 8.8 (HIGH) · EPSS 25th percentile

CWECWE 693VNDZipgeniusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:17Z
CRIT

CVE-2025-50329 — ConeXware: An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-50329

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. CVSSv3.1 9.8 (CRITICAL) · EPSS 28th percentile

CWECWE 693VNDConexwareTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-22
2026-07-22 21:17Z
HIGH

CVE-2025-50327 — Franco: An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-50327

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism CVSSv3.1 8.8 (HIGH) · EPSS 27th percentile

CWECWE 693VNDFrancoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:17Z
HIGH

CVE-2025-50324 — Milos: An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-50324

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. CVSSv3.1 8.8 (HIGH) · EPSS 25th percentile

CWECWE 693VNDMilosTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:17Z
HIGH

CVE-2025-44090 — OhSoft: An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-44090

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 693VNDOhsoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 21:17Z
HIGH

CVE-2025-44089 — NCH: An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-44089

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 693VNDNchTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 20:16Z
HIGH

CVE-2026-13072 — When compute mode is enabled on a standalone mongod instance, insufficient validation of externally

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13072

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup. CVSSv3.1 8.1 (HIGH)

CWECWE 122TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 20:16Z
HIGH

CVE-2026-13059 — An authenticated user with low privileges may be able to perform unauthorized reads and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13059

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations. CVSSv3.1 8.1 (HIGH)

CWECWE 807TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 19:32Z
CRIT

CVE-2026-60167, CVE-2026-60168, CVE-2026-60169 & CVE-2026-60170 | Oracle Hospitality Simphony Multiple Vulnerabilities

Horizon3.ai disclosed four critical vulnerabilities in Oracle Hospitality Simphony affecting versions 19.8–19.10, including UNC path coercion (NTLM hash disclosure), arbitrary file writes via the EGateway Printing Handler, and authentication bypass in the Kiosk application leading to RCE. All vulnerabilities are unauthenticated, network-exploitable, and patched in Oracle's July 2026 Critical Patch Update; no active exploitation in the wild has been confirmed.

SRFApplicationTACTA0004TACTA0001TACTA0002SRFNetworkTACTA0003SWOracle Hospitality SimphonyVNDOracle
82
Edit Score
2026-07-22
2026-07-22 19:16Z
HIGH

CVE-2026-22049 — Netapp Ontap: versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22049

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

CWECWE 288VNDNetappVNDOntapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 19:16Z
CRIT

CVE-2026-16624 — Cal: Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16624

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery. CVSSv3.1 9.6 (CRITICAL) · EPSS 10th percentile

CWECWE 639VNDCalTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-22
2026-07-22 18:17Z
HIGH

CVE-2026-64835 — FFmpeg: versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64835

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequ CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDFfmpegTYPVulnerability
8.8
CVSS v3.1
94
Edit Score