Vulnerabilities

Summary — last 7 days

New vulnerabilities2,716▼ 25 vs. last week
Critical / high1,269▼ 244 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

268 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.2)1.3%—Hitachienergy Counterparty Settlement AND BillingHitachienergy Retail Operations8/20/20216/17/2026
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids…
ModifiedCritical (9.8)1.1%—Water Billing System Project Water Billing System7/22/20216/17/2026
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
ModifiedHigh (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+1077/21/20218/25/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModifiedHigh (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+207/13/20216/17/2026
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModifiedHigh (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+227/13/20216/17/2026
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModifiedHigh (7.5)13%—Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+307/13/202110/8/2026
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
ModifiedHigh (7.5)11%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+237/13/202110/8/2026
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
ModifiedMedium (4.8)11%💥 PoCApache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+564/13/202110/7/2026
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling…
ModifiedLow (3.7)3.1%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+74/1/20216/17/2026
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server…
ModifiedMedium (5.3)5.3%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+84/1/20216/17/2026
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP…
AnalyzedCritical (9.1)82%💥 ExploitNetapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to…
AnalyzedCritical (9.8)15%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security…
AnalyzedHigh (8.6)47%💥 PoCNetapp Oncommand InsightApache ActivemqApache JmeterXstream+133/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed…
AnalyzedHigh (7.5)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security…
AnalyzedCritical (9.8)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalyzedCritical (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalyzedCritical (9.9)72%💥 ExploitNetapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the…
AnalyzedCritical (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+123/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalyzedHigh (7.5)47%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+113/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.…
AnalyzedHigh (7.5)78%💥 PoCNetapp Oncommand InsightApache ActivemqApache JmeterXstream+93/22/202110/7/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by…
ModifiedMedium (5.4)2.0%💥 ExploitUltimatekode NEO Billing3/2/20216/17/2026
Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML.
ModifiedHigh (7.8)1.1%💥 PoCGnupg LibgcryptOracle Communications Billing AND Revenue Management1/29/20216/17/2026
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
ModifiedMedium (4.3)0.80%—Oracle Financial Services Revenue Management AND Billing1/20/20216/17/2026
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: On Demand Billing). Supported versions that are affected are 2.9.0.0 and 2.9.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModifiedMedium (4.3)0.43%—Totalonlinesolutions Advanced Webhost Billing System1/8/20216/17/2026
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.
ModifiedHigh (8.1)4.1%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+411/7/20218/25/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.