Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,135
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 13,721 - 13,740 of 47,381 CVEs
CVE-2026-35275 HIGH - 7.5

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to comprom...

Vendor: oracle
Product: vm_virtualbox
Published: Jun 17, 2026
Source: NVD
CVE-2026-35274 HIGH - 8.2

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Ent...

Vendor: oracle
Product: peoplesoft_enterprise_pt_peopletools
Published: Jun 17, 2026
Source: NVD
CVE-2026-35272 HIGH - 8.4

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterpr...

Vendor: oracle
Product: peoplesoft_enterprise_pt_peopletools
Published: Jun 17, 2026
Source: NVD
CVE-2026-35271 HIGH - 8.7

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise ...

Vendor: oracle
Product: peoplesoft_enterprise_pt_peopletools
Published: Jun 17, 2026
Source: NVD
CVE-2026-35270 CRITICAL - 9.1

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebC...

Vendor: oracle
Product: webcenter_content
Published: Jun 17, 2026
Source: NVD
CVE-2026-35269 HIGH - 7.5

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager....

Vendor: oracle
Product: identity_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-35268 CRITICAL - 9.9

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Identity Manager. While t...

Vendor: oracle
Product: identity_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-35267 HIGH - 8.8

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. ...

Vendor: oracle
Product: identity_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-35265 HIGH - 8.8

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Success...

Vendor: oracle
Product: identity_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-35263 CRITICAL - 9.9

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. While the vul...

Vendor: oracle
Product: weblogic_server
Published: Jun 17, 2026
Source: NVD
CVE-2026-35262 HIGH - 8.3

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Inte...

Vendor: oracle
Product: data_integrator
Published: Jun 17, 2026
Source: NVD
CVE-2026-35261 MEDIUM - 6.5

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ...

Vendor: oracle
Product: access_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-35259 HIGH - 8.8

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise WebLogic Server. Successf...

Vendor: oracle
Product: weblogic_server
Published: Jun 17, 2026
Source: NVD
CVE-2026-35258 HIGH - 8.7

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise WebLogic Server. Successfu...

Vendor: oracle
Product: weblogic_server
Published: Jun 17, 2026
Source: NVD
CVE-2026-12348 HIGH - 7.4

Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.

Vendor: The Browser Company of New York`
Product: Arc Search
Published: Jun 17, 2026
Source: NVD

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown link and image URL schemes. In versions with scheme filtering, C0 control characters in the URL scheme could bypass the c...

Vendor: npm
Product: @mariozechner/pi-coding-agent
Published: Jun 16, 2026
Source: GitHub
CVE-2026-20706 MEDIUM - 9.1

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-27783 MEDIUM - 4.3

Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-25714 MEDIUM - 4.3

Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-26231 HIGH - 8.5

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub