2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-46994 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46994

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentia CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-46993 — Vulnerability: Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46993

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Su CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-46992 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46992

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-46989 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46989

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Succes CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-46983 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46983

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-46982 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46982

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impac CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-46924 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46924

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-46923 — Vulnerability: Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46923

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional product CVSSv3.1 8.0 (HIGH)

VNDVulnerabilityTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-46876 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46876

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S: CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
CRIT

CVE-2026-35290 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35290

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:17Z
HIGH

CVE-2026-10678 — MCTP: into a small attacker-advanceable offset above address 0), producing memory corruption or a hard

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10678

The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_target_write_received() without validating the order or the receive buffer. In the affected versions the MCTP_I2C_GPIO_RX_MSG_ADDR (data) handler dereferences and writes through b->rx_pkt without checking that the receive buffer was allocated: a controller that selects the data register and writes a byt CVSSv3.1 8.1 (HIGH)

CWECWE 787CWECWE 476VNDMctpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-8983 — Autel Maxicharger_single_charger_firmware: Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8983

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication. CVSSv3.1 9.8 (CRITICAL) · EPSS 25th percentile

CWECWE 798VNDAutelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 21:16Z
HIGH

CVE-2026-8982 — Autel Maxicharger_single_charger_firmware: Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8982

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges. CVSSv3.1 8.1 (HIGH) · EPSS 25th percentile

CWECWE 798VNDAutelVNDTwoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-65057 — Keep: (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65057

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud metadata endpoints, enabling theft of cloud credentials and internal network re CVSSv3.1 9.3 (CRITICAL)

CWECWE 918VNDKeepTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-21
2026-07-21 21:16Z
HIGH

CVE-2026-65056 — mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65056

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers can steer the LLM-controlled URL argument through prompt injection to navigate the server's Playwright browser to internal endpoints such as cloud instance metadat CVSSv3.1 8.2 (HIGH)

CWECWE 918TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 21:16Z
HIGH

CVE-2026-64881 — This input validation failure enables command injection when chained with a related vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64881

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-63764 — OpenAI: lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63764

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a crafted image_url that redirects to internal targets. Attackers can send a POST request to the chat completions endpoint with an image_url pointing to an attacker-controlled server that responds with an HTTP 302 redirect to internal addresses such as loopback or instance-metad CVSSv3.1 9.3 (CRITICAL)

CWECWE 918VNDOpenaiTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-52472 — SQL: injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52472

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-52470 — SQL: injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52470

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-52469 — SQL: injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52469

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 21:16Z
HIGH

CVE-2026-47688 — FOG: This allows remote wiping of host AES encryption credentials and deletion of all power

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47688

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. Versions CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDFogTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 21:16Z
HIGH

CVE-2026-47237 — Kubeflow: Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47237

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user's account and the data that is processed by that user. The CVSSv3.1 8.0 (HIGH)

CWECWE 266VNDKubeflowTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-21
2026-07-21 21:16Z
CRIT

CVE-2026-30631 — An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30631

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 20:17Z
CRIT

CVE-2026-64879 — A filename supplied during file upload is not properly sanitized before being used in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64879

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 20:17Z
CRIT

CVE-2026-64878 — Unvalidated: input in asset filter parameters allows shell metacharacters to escape command argument handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64878

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDUnvalidatedTYPVulnerability
9.9
CVSS v3.1
100
Edit Score