Common Vulnerabilities and Exposures (CVE)

CVE-2026-83111

Sep 16, 2026 17:57:49 UTC

Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker ...

CVE-2026-66887

Sep 16, 2026 17:57:45 UTC

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

CVE-2026-83123

Sep 16, 2026 17:57:42 UTC

Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n...

CVE-2026-83127

Sep 16, 2026 17:57:35 UTC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with ne...

CVE-2026-83128

Sep 16, 2026 17:57:29 UTC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with n...

CVE-2026-83129

Sep 16, 2026 17:57:23 UTC

Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ac...

CVE-2026-83130

Sep 16, 2026 17:57:17 UTC

Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network...

CVE-2026-83131

Sep 16, 2026 17:57:12 UTC

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged ...

CVE-2026-83133

Sep 16, 2026 17:57:06 UTC

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access...

CVE-2026-79994

Sep 16, 2026 17:57:02 UTC

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink b...

CVE-2026-88593

Sep 16, 2026 17:56:52 UTC

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates ...

CVE-2026-73455

Sep 16, 2026 17:56:12 UTC

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.

CVE-2026-68950

Sep 16, 2026 17:55:44 UTC

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

CVE-2026-68070

Sep 16, 2026 17:55:13 UTC

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

CVE-2026-66890

Sep 16, 2026 17:54:33 UTC

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.