Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,720
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,201 - 6,220 of 35,133 CVEs
CVE-2026-9645 CRITICAL - 9.9

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

Published: May 28, 2026
Source: NVD
CVE-2026-49095 MEDIUM - 6.5

Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism that is not adequately...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-49094 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kibana will consume exces...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-49093 MEDIUM - 6.3

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-46843 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46842 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46841 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability ...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46840 CRITICAL - 10.0

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is i...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46839 CRITICAL - 9.9

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Dat...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46837 HIGH - 8.8

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Suc...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46835 HIGH - 7.5

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result...

Vendor: oracle
Product: database_server
Published: May 28, 2026
Source: NVD
CVE-2026-46834 HIGH - 7.5

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result...

Vendor: oracle
Product: database_server
Published: May 28, 2026
Source: NVD
CVE-2026-46833 CRITICAL - 9.0

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attack...

Vendor: oracle
Product: database_server
Published: May 28, 2026
Source: NVD
CVE-2026-46830 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46829 HIGH - 7.5

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46828 HIGH - 8.1

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful at...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46827 HIGH - 8.8

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful a...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46826 HIGH - 8.8

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful a...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46824 CRITICAL - 9.9

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromi...

Vendor: oracle
Product: universal_work_queue
Published: May 28, 2026
Source: NVD
CVE-2026-46823 HIGH - 7.7

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

Vendor: oracle
Product: public_sector_financials
Published: May 28, 2026
Source: NVD