|
1071
|
9.0 |
CRITICAL
Network
|
oracle
|
database_server
|
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with…
Update
|
NVD-CWE-noinfo
|
CVE-2026-46833
|
2026-06-4 03:12 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1072
|
8.1 |
HIGH
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acc…
Update
|
CWE-400 CWE-284
Uncontrolled Resource Consumption Improper Access Control
|
CVE-2026-35277
|
2026-06-4 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1073
|
7.9 |
HIGH
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network a…
Update
|
CWE-400 CWE-352
Uncontrolled Resource Consumption Origin Validation Error
|
CVE-2026-35266
|
2026-06-4 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1074
|
7.5 |
HIGH
Network
|
hkuds
|
deepcode
|
DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying…
Update
|
CWE-22
Path Traversal
|
CVE-2026-32847
|
2026-06-4 03:02 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1075
|
9.1 |
CRITICAL
Network
|
electerm_project
|
electerm
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
Update
|
CWE-326 CWE-329 CWE-353 CWE-759 CWE-916
Inadequate Encryption Strength Not Using a Random IV with CBC Mode Missing Support for Integrity Check Use of a One-Way Hash without a Salt Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-45787
|
2026-06-4 02:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1076
|
7.8 |
HIGH
Local
|
electerm_project
|
electerm
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
Update
|
CWE-94 CWE-732 CWE-940
Code Injection Incorrect Permission Assignment for Critical Resource Improper Verification of Source of a Communication Channel
|
CVE-2026-45353
|
2026-06-4 02:54 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1077
|
8.8 |
HIGH
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-46826
|
2026-06-4 02:43 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1078
|
8.8 |
HIGH
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability al…
Update
|
CWE-269 CWE-284 CWE-287 CWE-306
Improper Privilege Management Improper Access Control Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-46827
|
2026-06-4 02:43 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1079
|
8.1 |
HIGH
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-46828
|
2026-06-4 02:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1080
|
7.5 |
HIGH
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-46829
|
2026-06-4 02:41 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|