Vulnerabilities
Summary — last 7 days
New vulnerabilities3,062▲ 584 vs. last week
Critical / high1,459▲ 293 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
61 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (4) | 0.27% | — | Adobe Genuine Software Integrity ServiceAI | 8/7/2026 | 8/17/2026 | Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require… | |
| Analyzed | Medium (4.4) | 0.14% | — | Fortra File Integrity Monitoring | 6/23/2026 | 6/29/2026 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships. | |
| Analyzed | Medium (4.8) | 0.24% | — | Fortra File Integrity Monitoring | 6/23/2026 | 6/28/2026 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store… | |
| Analyzed | Medium (6.5) | 0.13% | — | Pcisig PCI Express Integrity AND Data Encryption | 12/9/2025 | 6/17/2026 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device rebinding may allow stale write transactions from a previous security context to be processed in a new one. This can lead to unintended data… | |
| Analyzed | Medium (6.5) | 0.21% | — | Pcisig PCI Express Integrity AND Data Encryption | 12/9/2025 | 6/17/2026 | A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completions being delivered… | |
| Analyzed | Medium (5.1) | 0.14% | — | Pcisig PCI Express Integrity AND Data Encryption | 12/9/2025 | 6/17/2026 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness may allow encrypted packets to be replayed or reordered without detection. This can enable local or physical attackers on the… | |
| Deferred | Medium (4.3) | 0.28% | — | Meitar Subresource Integrity SRI ManagerAI | 9/22/2025 | 6/17/2026 | Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0. | |
| Deferred | High (7.4) | 0.28% | — | Microsoft Windows Defender Application ControlAIMicrosoft Hypervisor-protected Code IntegrityAI | 9/8/2025 | 6/17/2026 | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier… | |
| Deferred | Critical (9.1) | 0.64% | — | Bentley Alim WEBAIBentley Assetwise Alim WEBAIBentley Assetwise Information Integrity ServerAI | 2/26/2024 | 6/17/2026 | In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03. | |
| Modified | High (7.8) | 0.17% | — | HPE SGI UV 300 RMC FirmwareHPE Integrity Mc990 X Server RMC Firmware | 6/16/2023 | 6/17/2026 | The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege. | |
| Modified | Medium (6.1) | 1.6% | — | EQS Integrity Line | 7/7/2022 | 6/17/2026 | EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry. | |
| Modified | High (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 1/18/2022 | 6/17/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modified | Critical (9.8) | 67% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 1/18/2022 | 6/17/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modified | High (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 1/18/2022 | 6/17/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modified | Medium (5.9) | 100% | — | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 12/18/2021 | 8/25/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modified | High (7.5) | 81% | — | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 12/14/2021 | 6/17/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modified | High (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 7/21/2021 | 8/25/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modified | Medium (6.5) | 10% | — | Eclipse MojarraOracle Banking Enterprise Default ManagementOracle Banking PlatformOracle Communications Network Integrity+5 | 6/2/2021 | 6/17/2026 | Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. | |
| Modified | High (7.8) | 0.40% | — | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRM - Elastic Charging EngineOracle Communications Cloud Native Core Binding Support Function+28 | 5/27/2021 | 6/17/2026 | In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or… | |
| Modified | High (8.8) | 23% | — | Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+12 | 3/10/2021 | 6/17/2026 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine… | |
| Modified | Low (3.7) | 0.52% | — | Webpack-subresource-integrity Project Webpack-subresource-integrity | 10/19/2020 | 6/17/2026 | In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are… | |
| Modified | High (7.8) | 0.94% | — | Adobe Genuine Integrity Service | 3/25/2020 | 6/17/2026 | Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modified | Critical (9.8) | 69% | — | Apache Log4jDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+13 | 12/20/2019 | 6/17/2026 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. | |
| Modified | Medium (6.1) | 2.2% | — | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 11/8/2019 | 8/25/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modified | Critical (9.8) | 14% | — | Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+18 | 10/16/2019 | 6/17/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and… |