Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthent…

Jul 21, 2026 Aug 06, 2026
Jul 21, 2026
Aug 06, 2026
5.9 MEDIUM

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0…

Jul 21, 2026 Jul 31, 2026
Jul 21, 2026
Jul 31, 2026
7.2 HIGH

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabili…

human_resources | Remote
Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
4.6 MEDIUM

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.32, 2.5.0.1…

Jul 21, 2026 Aug 06, 2026
Jul 21, 2026
Aug 06, 2026
7.4 HIGH

Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability …

retail_eftlink | Remote
Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
7.5 HIGH

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerabil…

Jul 21, 2026 Aug 17, 2026
Jul 21, 2026
Aug 17, 2026
4.4 MEDIUM

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.…

Jul 21, 2026 Jul 27, 2026
Jul 21, 2026
Jul 27, 2026
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP t…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.0 HIGH

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult…

Jul 21, 2026 Aug 06, 2026
Jul 21, 2026
Aug 06, 2026
5.3 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 1…

Jul 21, 2026 Aug 03, 2026
Jul 21, 2026
Aug 03, 2026
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracl…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.9 HIGH
CVE-2026-43947 — FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorizati…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /ap…

fuxa | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.7 HIGH
CVE-2026-43946 — FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when t…

fuxa | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.9 HIGH
CVE-2026-43945 — FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The…

fuxa | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP t…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.5 HIGH

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP t…

Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
6.1 MEDIUM

Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerabili…

Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
4.3 MEDIUM

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vul…

Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
3.3 LOW

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vul…

Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-16484 — SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argu…

class_and_exam_timetabling_system | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
Showing 20 of 12347 Results