U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-18144 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
    Published: August 12, 2026; 1:17:25 PM -0400

  • CVE-2026-46939 - Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit... read CVE-2026-46939
    Published: June 17, 2026; 6:54:13 AM -0400

  • CVE-2026-18683 - IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
    Published: August 12, 2026; 1:17:25 PM -0400

  • CVE-2026-61311 - Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acc... read CVE-2026-61311
    Published: July 21, 2026; 6:18:59 PM -0400

  • CVE-2026-61312 - Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network a... read CVE-2026-61312
    Published: July 21, 2026; 6:18:59 PM -0400

  • CVE-2026-61091 - Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vu... read CVE-2026-61091
    Published: July 21, 2026; 6:18:40 PM -0400

  • CVE-2026-61126 - Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulner... read CVE-2026-61126
    Published: July 21, 2026; 6:18:43 PM -0400

  • CVE-2026-61125 - Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit... read CVE-2026-61125
    Published: July 21, 2026; 6:18:43 PM -0400

  • CVE-2026-17082 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.
    Published: August 12, 2026; 4:17:39 PM -0400

  • CVE-2026-61105 - Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attack... read CVE-2026-61105
    Published: July 21, 2026; 6:18:41 PM -0400

  • CVE-2026-61102 - Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attack... read CVE-2026-61102
    Published: July 21, 2026; 6:18:41 PM -0400

  • CVE-2026-61097 - Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenti... read CVE-2026-61097
    Published: July 21, 2026; 6:18:40 PM -0400

  • CVE-2026-61095 - Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and 8.0.1. Easily exploitable vulnerabilit... read CVE-2026-61095
    Published: July 21, 2026; 6:18:40 PM -0400

  • CVE-2026-16694 - IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials... read CVE-2026-16694
    Published: August 12, 2026; 1:17:23 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2026-62525 - Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netwo... read CVE-2026-62525
    Published: July 21, 2026; 6:19:07 PM -0400

  • CVE-2026-61200 - Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netw... read CVE-2026-61200
    Published: July 21, 2026; 6:18:51 PM -0400

  • CVE-2026-49163 - Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
    Published: August 06, 2026; 8:16:30 PM -0400

  • CVE-2026-60962 - Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netw... read CVE-2026-60962
    Published: July 21, 2026; 6:18:30 PM -0400

  • CVE-2026-17094 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
    Published: August 12, 2026; 1:17:24 PM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-18098 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
    Published: August 12, 2026; 1:17:24 PM -0400

Created September 20, 2022 , Updated August 27, 2024