Vulnerabilities

Summary — last 7 days

New vulnerabilities2,743▼ 518 vs. last week
Critical / high1,293▼ 226 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)244▼ 258 vs. last week
–

168 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.2)21%💥 ExploitLodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+192/15/20216/17/2026
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
ModifiedMedium (5.3)7.3%—LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+152/15/20216/17/2026
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
ModifiedMedium (5.5)1.8%—NettyDebian LinuxQuarkusOracle Banking Corporate Lending Process Management+92/8/20216/17/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are…
AnalyzedHigh (8.1)5.0%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/7/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
ModifiedHigh (8.1)4.1%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/7/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
ModifiedHigh (8.1)4.1%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+411/7/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
ModifiedHigh (8.1)17%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+391/7/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
ModifiedHigh (8.1)8.8%💥 PoCFasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/6/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
ModifiedHigh (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/6/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
ModifiedHigh (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/6/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
ModifiedHigh (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/6/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
ModifiedHigh (8.1)8.4%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+411/6/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
ModifiedHigh (8.1)4.1%—Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+401/6/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
AnalyzedHigh (8.1)13%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+3612/27/20208/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
ModifiedHigh (8.1)7.2%💥 PoCBouncycastle Bc-javaApache KarafOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+1612/18/20206/17/2026
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
AnalyzedHigh (8.8)85%💥 ExploitXstreamDebian LinuxNetapp SnapmanagerApache Activemq+1111/16/202010/7/2026
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The…
ModifiedMedium (6.5)1.5%—Oracle Banking Corporate Lending10/21/20206/17/2026
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0 and 14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking…
ModifiedHigh (8.1)7.3%💥 PoCFasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+229/17/20208/25/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
ModifiedCritical (9.8)4.4%—Vmware Spring IntegrationOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Supply Chain Finance+47/31/20206/17/2026
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution…
ModifiedHigh (7.4)5.2%—LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+147/15/20206/17/2026
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
ModifiedCritical (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+593/10/20206/17/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModifiedMedium (4.3)0.94%—Oracle Banking Corporate Lending1/15/20206/17/2026
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking…
ModifiedHigh (7.1)1.1%—Oracle Banking Corporate Lending1/15/20206/17/2026
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking…
ModifiedMedium (5.4)1.1%—Oracle Banking Corporate Lending1/15/20206/17/2026
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking…
ModifiedMedium (6.5)1.3%—Oracle Banking Corporate Lending1/15/20206/17/2026
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking…
Orbitaley — Vulnerabilities