2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60460 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60460

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidenti CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60459 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60459

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Success CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60458 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60458

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Suc CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60457 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60457

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Suc CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60456 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60456

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Success CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60452 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60452

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability ca CVSSv3.1 8.5 (HIGH)

VNDVulnerabilityTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60450 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60450

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60448 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60448

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabi CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60447 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60447

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Success CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60446 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60446

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidenti CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60445 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60445

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Suc CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60444 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60444

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabilit CVSSv3.1 8.5 (HIGH)

VNDVulnerabilityTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60443 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60443

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significan CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60442 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60442

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avail CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60441 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60441

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avail CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60438 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60438

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as u CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60437 — Vulnerability: Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60437

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60435 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60435

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60431 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60431

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unaut CVSSv3.1 8.6 (HIGH)

VNDVulnerabilityTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60430 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60430

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60429 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60429

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60428 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60428

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60427 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60427

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability c CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-60426 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60426

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can CVSSv3.1 8.5 (HIGH)

VNDVulnerabilityTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-60424 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60424

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability c CVSSv3.1 9.0 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.0
CVSS v3.1
95
Edit Score