Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
7.5 HIGH

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
8.1 HIGH

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
8.8 HIGH

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability al…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
8.8 HIGH

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
9.9 CRITICAL

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Eas…

May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.7 HIGH

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily ex…

May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.9 CRITICAL

Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…

iassets | Remote
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.7 HIGH

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v…

May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.5 HIGH

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v…

May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
9.1 CRITICAL

Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploi…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
7.4 HIGH

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability al…

May 28, 2026 Jun 04, 2026
May 28, 2026
Jun 04, 2026
9.8 CRITICAL

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allo…

May 28, 2026 Jun 04, 2026
May 28, 2026
Jun 04, 2026
9.9 CRITICAL

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acc…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
9.8 CRITICAL
CVE-2026-45288 — Marten has an SQL injection vulnerability in its full-text search regConfig parameter

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generate…

Remote | Injection
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-44657 — MantisBT: Stored XSS in File Download

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execu…

mantisbt | Remote | Cross-Site Request Forgery
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.6 HIGH
CVE-2026-44655 — MantisBT: Stored XSS on Move Attachments Admin Page

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator acces…

mantisbt | Remote | Cross-Site Scripting
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-42400 — Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload…

kibana | Remote | Denial of Service
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-42399 — Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentiall…

kibana | Remote | Denial of Service
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.7 HIGH
CVE-2026-42398 — Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connec…

kibana | Remote | Server-Side Request Forgery
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
Showing 20 of 7197 Results