Latest CVE Feed
-
6.4
MEDIUMCVE-2025-50071
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access... Read more
Affected Products : applications_framework- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-50068
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with logon to ... Read more
Affected Products : mysql_cluster- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
9.0
CRITICALCVE-2025-50067
Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromis... Read more
Affected Products : application_express- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
2.7
LOWCVE-2025-50066
Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-53867
Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
-
9.8
CRITICALCVE-2025-52046
Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted requ... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-51497
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be d... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2024-32323
SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information via the if parameter in hcit.project.rte.agents.UploadImages.class.... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-47356
Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/fw_security.mds.... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2023-41566
OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerability allows attackers to obtain the password of the background administrator and further obtain database permissions... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2025-50064
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with netw... Read more
Affected Products : weblogic_server- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-50061
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.0-20.12.21, 21.12.0-21.12.21, 22.12.0-22.12.19, 23.12.0-23.12... Read more
Affected Products : primavera_p6_enterprise_project_portfolio_management- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-50060
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network acce... Read more
Affected Products : bi_publisher- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-30762
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with netw... Read more
Affected Products : weblogic_server- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-30760
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.3. Easily exploitable vulnerability allows low privileged attacker with network access v... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-30759
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauth... Read more
Affected Products : business_intelligence- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
4.9
MEDIUMCVE-2025-53032
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to... Read more
Affected Products : mysql_server- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-53031
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.8, 8.0.8.5, 8.0.8.6, 8.1.1.4 and 8.1.2.5. Easil... Read more
Affected Products : financial_services_analytical_applications_infrastructure- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-50108
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected is 11.2.20.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via ... Read more
Affected Products : hyperion_financial_reporting- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-50107
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network acce... Read more
Affected Products : universal_work_queue- Published: Jul. 15, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication