Vulnerabilities
Summary — last 7 days
New vulnerabilities2,838▼ 146 vs. last week
Critical / high1,377▲ 68 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)255▼ 268 vs. last week
112 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/31/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.8) | 0.51% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/31/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.8) | 0.51% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 7/21/2026 | 7/24/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Deferred | Critical (9.1) | 0.86% | — | Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI | 7/21/2026 | 7/23/2026 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In… | |
| Deferred | High (7.1) | 0.47% | — | Samsung CaptureAI | 7/15/2026 | 7/16/2026 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies, browser storage, HTTP credentials, proxy… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analyzed | Critical (10) | 0.51% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3 to compromise Oracle WebCenter… | |
| Analyzed | Critical (10) | 0.51% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/26/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/23/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/23/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/23/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/23/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/23/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 6/17/2026 | 6/23/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analyzed | Medium (6.6) | 0.54% | — | Lookyloo Playwright Capture | 5/13/2026 | 6/17/2026 | PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the… | |
| Awaiting Analysis | Critical (9.3) | 0.88% | — | Kofax CaptureAIKofax Tungsten CaptureAI | 4/23/2026 | 6/17/2026 | Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote… | |
| Deferred | Critical (9.8) | 1.8% | — | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 3/19/2026 | 6/17/2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. |