Skip to main content

Severity archive

Critical severity CVEs

Critical

43,849 critical severity CVEs — 43,849 Critical, 126,422 High, 163,803 Medium, 18,046 Low, 1,857 Unrated across the current result set.

CVE-2026-60199

Published Jul 21, 2026

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60198

Published Jul 21, 2026

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60197

Published Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60173

Published Jul 21, 2026

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60168

Published Jul 21, 2026

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-47731

Published Jul 21, 2026

The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47056

Published Jul 21, 2026

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Ea…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-47040

Published Jul 21, 2026

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploita…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-47036

Published Jul 21, 2026

Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploita…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-46994

Published Jul 21, 2026

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46989

Published Jul 21, 2026

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46983

Published Jul 21, 2026

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploi…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46982

Published Jul 21, 2026

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily expl…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46924

Published Jul 21, 2026

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with netw…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46876

Published Jul 21, 2026

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with netw…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35290

Published Jul 21, 2026

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with netw…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8983

Published Jul 21, 2026

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker ca…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-8982

Published Jul 21, 2026

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-s…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65057

Published Jul 21, 2026

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying att…

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-52472

Published Jul 21, 2026

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-52470

Published Jul 21, 2026

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-52469

Published Jul 21, 2026

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47708

Published Jul 21, 2026

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpo…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-30631

Published Jul 21, 2026

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_wr…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-64879

Published Jul 21, 2026

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve com…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Showing 601-625 of 43,849 CVEsPage 25 of 1754