2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60200 | CRITICAL | 9.8 | 0.5% | Jul 21, 2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2026-60199 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2026-60198 | CRITICAL | 9.8 | 0.5% | Jul 21, 2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2026-60197 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar... |
| CVE-2026-60173 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi... |
| CVE-2026-60168 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Sup... |
| CVE-2026-47731 | CRITICAL | 9.1 | 0.8% | Jul 21, 2026 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based... |
| CVE-2026-47056 | CRITICAL | 10 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported ve... |
| CVE-2026-47040 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are ... |
| CVE-2026-47036 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supporte... |
| CVE-2026-46994 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next... |
| CVE-2026-46989 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framewo... |
| CVE-2026-46983 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The ... |
| CVE-2026-46982 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The ... |
| CVE-2026-46924 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita... |
| CVE-2026-46876 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita... |
| CVE-2026-35290 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita... |
| CVE-2026-8983 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati... |
| CVE-2026-65057 | CRITICAL | 9.3 | 0.2% | Jul 21, 2026 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make... |
| CVE-2026-52472 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml ... |
| CVE-2026-52470 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper... |
| CVE-2026-52469 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.... |
| CVE-2026-47708 | CRITICAL | 9.3 | 0.3% | Jul 21, 2026 | MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` ... |
| CVE-2026-30631 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers... |
| CVE-2026-64879 | CRITICAL | 9.9 | 2.6% | Jul 21, 2026 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now