Vulnerabilities

Summary — last 7 days

New vulnerabilities2,764▲ 64 vs. last week
Critical / high1,288▼ 208 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

268 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.9)1.1%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModifiedCritical (10)1.8%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModifiedLow (3.3)0.32%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…
ModifiedLow (3.3)0.32%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…
ModifiedHigh (7.5)1.7%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModifiedHigh (8.8)54%—Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+221/18/20226/17/2026
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
ModifiedCritical (9.8)67%💥 PoCApache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+241/18/20226/17/2026
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or…
ModifiedHigh (8.8)64%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+221/18/20226/17/2026
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink…
ModifiedMedium (5.9)100%💥 PoCApache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11212/18/20218/25/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModifiedHigh (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4212/14/20216/17/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModifiedHigh (7.1)0.26%—Hitachienergy Counterparty Settlements AND BillingHitachienergy Retail Operations11/17/20216/17/2026
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data…
AnalyzedHigh (8.5)98%⚠ Active exploitation💥 ExploitXstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+118/23/20216/17/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)11%💥 ExploitXstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,…
AnalyzedHigh (8.5)3.4%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,…
AnalyzedMedium (6.3)5.9%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed…
AnalyzedHigh (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)4.5%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+98/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or…
AnalyzedHigh (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)14%💥 ExploitXstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)4.1%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.5)16%💥 ExploitXstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalyzedHigh (8.8)4.5%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+118/23/202110/7/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21…
Orbitaley — Vulnerabilities