Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privilege…

Jul 21, 2026 Jul 28, 2026
Jul 21, 2026
Jul 28, 2026
5.2 MEDIUM

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulne…

Jul 21, 2026 Jul 28, 2026
Jul 21, 2026
Jul 28, 2026
6.5 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java S…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.1 MEDIUM

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploit…

access_manager | Remote
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
4.9 MEDIUM

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Clust…

Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
3.6 LOW

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulne…

Jul 21, 2026 Jul 28, 2026
Jul 21, 2026
Jul 28, 2026
7.3 HIGH

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnera…

workflow | Remote
Jul 21, 2026 Jul 28, 2026
Jul 21, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-56816 — Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to …

netty | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-56746 — Netty has a Security Control Bypass via CORS Short-Circuit Failure

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security c…

netty | Remote | Misconfiguration
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.7 HIGH
CVE-2026-56745 — Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaus…

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` han…

netty | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.7 HIGH
CVE-2026-55851 — Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unb…

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1…

netty | Remote | Denial of Service
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.1 CRITICAL
CVE-2026-47731 — NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be …

The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground…

Remote | Path Traversal
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-47709 — libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malforme…

libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item h…

libheif | Memory Corruption
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
6.1 MEDIUM
CVE-2026-47254 — libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vect…

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks…

libheif | Memory Corruption
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
6.8 MEDIUM
CVE-2026-47251 — libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_da…

libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself…

libheif | Memory Corruption
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-47247 — libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixe…

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker …

libheif | Remote | Information Disclosure
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
7.8 HIGH
CVE-2026-47178 — libheif has Heap Out Of Bounds Write in unci subsystem

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out…

libheif | Memory Corruption
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
6.5 MEDIUM

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Clust…

Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
7.5 HIGH

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java …

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
5.5 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privilege…

Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
Showing 20 of 9545 Results