2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-65317 — Verba: RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65317

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and por CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDVerbaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:19Z
CRIT

CVE-2026-62549 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62549

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, d CVSSv3.1 9.6 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62547 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62547

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
CRIT

CVE-2026-62546 — Vulnerability: Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62546

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabil CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62534 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62534

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability i CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62530 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62530

Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (France) accessible data as well as unautho CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62516 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62516

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Demantra Demand Management. Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avail CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62514 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62514

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critica CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62513 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62513

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additi CVSSv3.1 8.5 (HIGH)

VNDVulnerabilityTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62504 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62504

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as wel CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62498 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62498

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts) CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62497 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62497

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessibl CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62496 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62496

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS V CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62494 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62494

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as wel CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62478 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62478

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Ava CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62476 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62476

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62473 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62473

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as we CVSSv3.1 8.3 (HIGH)

VNDVulnerabilityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62472 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62472

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as we CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62468 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62468

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible d CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62464 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62464

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62456 — Vulnerability: Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62456

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62451 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62451

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62447 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62447

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in takeover of Oracle Trade Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-62445 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62445

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-61338 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61338

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration a CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score