Vulnerabilities
Summary — last 7 days
New vulnerabilities3,075▲ 488 vs. last week
Critical / high1,457▲ 57 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
4,643 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.5) | 0.46% | — | Oracle Database ServerAIOracle NET ServicesAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can… | |
| Deferred | High (8.8) | 0.42% | — | Oracle Siebel Apps Self ServiceAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks of… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Service Delivery PlatformAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.… | |
| Deferred | High (7.7) | 0.34% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. While the… | |
| Deferred | Medium (6.5) | 0.34% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Deferred | High (7.1) | 0.29% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks… | |
| Awaiting Analysis | High (7.6) | 0.31% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Service Delivery PlatformAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Awaiting Analysis | Critical (9.9) | 0.42% | — | Oracle Service Delivery PlatformAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Awaiting Analysis | Critical (9.9) | 0.42% | — | Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery… | |
| Awaiting Analysis | Critical (9.9) | 0.42% | — | Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery… | |
| Awaiting Analysis | Critical (9.3) | 1.1% | — | Tencent Mass Service EngineAI | 9/15/2026 | 9/22/2026 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root. | |
| Deferred | High (7.4) | 0.36% | — | Oracle WEB Services ManagerAI | 9/15/2026 | 9/21/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Web Services… | |
| Deferred | High (8.2) | 0.34% | — | Oracle WEB Services ManagerAI | 9/15/2026 | 9/21/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services… | |
| Deferred | Medium (5.4) | 0.21% | — | Oracle Field ServiceAI | 9/15/2026 | 9/21/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks… | |
| Deferred | Critical (9.1) | 0.47% | — | Oracle Siebel Apps - Financial ServicesAI | 9/15/2026 | 9/21/2026 | Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services.… | |
| Awaiting Analysis | High (7.1) | 0.32% | — | Atlassian Jira Service Management Data CenterAI | 9/15/2026 | 9/17/2026 | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 | |
| Awaiting Analysis | Medium (5.9) | 0.41% | — | Redhat Service InterconnectAIRedhat Skupper RouterAI | 9/10/2026 | 9/14/2026 | A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing,… | |
| Deferred | High (8.6) | 0.60% | — | Behavioral Technology Group PavlokAIApple Notification Center ServiceAI | 9/10/2026 | 9/10/2026 | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local… | |
| Awaiting Analysis | Medium (6.6) | 0.31% | — | Tanium Data ServiceAI | 9/9/2026 | 9/9/2026 | Tanium addressed a path traversal vulnerability in Tanium Data Service. | |
| Analyzed | High (7.8) | 0.30% | — | Microsoft Xbox Gaming Services | 9/8/2026 | 9/14/2026 | Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally. | |
| Deferred | High (8.8) | 0.24% | — | TAC Information Services Internal AND External Trade INC Goldenhorn OneitAI | 9/4/2026 | 9/8/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. | |
| Deferred | High (7) | 0.34% | — | BR Industrial Automation Gmbh Mapp AuditAIBR Industrial Automation Gmbh Mapp ServicesAI | 9/3/2026 | 9/3/2026 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. | |
| Analyzed | Low (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 9/2/2026 | 9/15/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Deferred | Critical (9.8) | 0.61% | — | Fast-note-sync-serviceAI | 9/1/2026 | 9/8/2026 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey |