Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.…

Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP t…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.0 HIGH

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
5.3 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 1…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracl…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.9 HIGH
CVE-2026-43947 — FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorizati…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /ap…

fuxa | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.7 HIGH
CVE-2026-43946 — FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when t…

fuxa | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.9 HIGH
CVE-2026-43945 — FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The…

fuxa | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP t…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.5 HIGH

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP t…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
6.1 MEDIUM

Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerabili…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
4.3 MEDIUM

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vul…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.3 LOW

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vul…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-16484 — SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argu…

class_and_exam_timetabling_system | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.6 HIGH
CVE-2026-10680 — Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t`…

The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2cap_br.c validated the minimum command size against buf->len (the bytes re…

zephyr zephyr | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
3.3 LOW
CVE-2026-10679 — Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)

The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->frequency without validating config->frequency. spi_transceive is a Zephyr __…

zephyr zephyr | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-10678 — NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an un…

The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_target_write_received()…

zephyr zephyr | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-10677 — Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the…

The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object ha…

zephyr zephyr | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.3 MEDIUM
CVE-2026-10675 — Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (r…

In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provisioning protocol watchdog timer unconditionally at the top of the function…

zephyr zephyr | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.5 MEDIUM
CVE-2026-10674 — DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disa…

The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called LPUART_Deinit() at the start of mcux_lpuart_configure(), which disables the…

zephyr zephyr | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
Showing 20 of 9562 Results