Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 18 August 2026

RSS

1905 vulnerabilities published on 18 August 2026

Severity:
Oracle Hyperion Financial Management Security Risk: Unauthorized Data Access
CVE-2026-70921
The Oracle Hyperion Financial Management software version 11.2.25.0.000 has a security flaw that could allow an attacker to access and modify sensitive data without being authorized. This could impact...
10.0
Oracle Hyperion Data Relationship Management Access Security Breach (11.2.25.0.000)
CVE-2026-70880
An attacker can access and take control of Oracle Hyperion Data Relationship Management without a password. This can impact other connected systems, so it's essential to update the software to a secur...
10.0
Oracle Internet Directory: Unauthenticated Takeover via LDAP
CVE-2026-61241
Oracle Internet Directory, used in Oracle Fusion Middleware, has a security flaw that allows an attacker to take control of the system without a password. This could impact not only Oracle Internet Di...
10.0
Kobako Sandbox Escape: Untrusted Ruby Code Execution
GHSA-7pwq-q9jf-539h CVE-2026-55107
An attacker can run arbitrary Ruby code in the host process, potentially reading or modifying host data, spawning processes, and more. This is a serious issue because it defeats the purpose of the Kob...
10.0
TRENDnet TEW-WLC100: Unsecured Server Header Leads to Remote Attack
CVE-2026-75784
A security flaw in TRENDnet's TEW-WLC100 allows a hacker to remotely attack the device by manipulating a server header. This means a malicious person can access the device from anywhere, potentially c...
9.3
WordPress WP Compress Remote Code Execution
CVE-2026-73343
A security issue in older versions of WP Compress allows hackers to run malicious code on your website without needing a password. This could lead to unauthorized changes or data theft. Update to vers...
10.0
Firefox: Unprivileged Code Execution in Remote Settings
UBUNTU-CVE-2026-75874 CVE-2026-75874 DEBIAN-CVE-2026-75874
The Firefox Remote Settings Client component allows unauthorized code to run with elevated privileges, potentially allowing an attacker to execute malicious code. This issue affects Firefox users who ...
10.0
Oracle Analytics BI Publisher Web Service API Takeover Risk
CVE-2026-71059
If you use Oracle Analytics, a hacker with limited access could take control of your BI Publisher service. This is serious because it could affect other connected systems. To protect your business, up...
9.9
Oracle Hyperion Financial Management: SQL Attack via Network
CVE-2026-70920
A hacker with network access can exploit a weakness in Oracle Hyperion Financial Management, potentially taking control of the system. This could impact other connected products as well. Affected user...
9.9
Oracle Siebel CRM Open Integration HTTP Takeover
CVE-2026-62588
Oracle Siebel CRM versions 25.12 to 26.6 have a security flaw that allows an attacker with network access to take control of the integration product. This could impact other connected products, so it'...
9.9
Oracle Siebel CRM Cloud Applications: Unsecured Access via HTTP
CVE-2026-61317
If an attacker with limited access can connect to your Oracle Siebel CRM Cloud Applications via the internet, they might be able to take control of the entire system. This could happen if you're using...
9.9
Oracle WebCenter Sites: Unsecured Access via HTTP
CVE-2026-61021
Oracle WebCenter Sites, a product of Oracle Fusion Middleware, has a security weakness that makes it easy for attackers with network access to take control of the system. This could impact not just We...
9.9
Oracle Fusion Middleware MFT Runtime Server Security Risk: Takeover
CVE-2026-61003
Oracle Fusion Middleware's MFT Runtime Server has a security weakness that allows an attacker with network access to take control of the system. This affects versions 12.2.1.4.0 and 14.1.2.0.0. We rec...
9.9
Oracle WebCenter Enterprise Capture: Unauthorized Data Access and DOS
CVE-2026-60916
The Oracle WebCenter Enterprise Capture product, used for document capture and management, has a vulnerability that allows unauthorized access to sensitive data and can cause partial system downtime. ...
9.9
Oracle WebCenter Portal Composer Takeover Risk in Oracle Fusion Middleware
CVE-2026-60730
Oracle WebCenter Portal Composer in versions 12.2.1.4.0 and 14.1.2.0.0 is at risk of being taken over by an attacker with network access. This could impact not just the Portal, but other connected pro...
9.9
Oracle Identity Manager: Takeover of the System
CVE-2026-60720
The Oracle Identity Manager, part of Oracle Fusion Middleware, has a security issue that allows an attacker to take control of the system. This means that an attacker can access and manipulate sensiti...
9.9
Oracle WebLogic Server: Unsecured Access to Critical System
CVE-2026-60702
Oracle WebLogic Server's core component is at risk of being taken over by an attacker with network access. This could lead to unauthorized access to sensitive data and disruption of critical services....
9.9
Oracle Helidon Imperative Web Server Allows Unauthorized Access
CVE-2026-73930
An attacker can access sensitive data and disrupt Oracle Helidon without a password. This affects Helidon version 4.5.3 and potentially other products. Update Helidon to a fixed version to prevent una...
9.9
Oracle Reports Developer Security Flaw on Oracle Fusion Middleware
CVE-2026-62608
A security flaw in Oracle Reports Developer on Oracle Fusion Middleware 12.2.1.19.0 allows an attacker with network access to take control of the system. This could impact other products as well. Orac...
9.9
Oracle Siebel CRM Cloud Manager Takeover via HTTP
CVE-2026-62512
A critical vulnerability in Oracle Siebel CRM Cloud Manager allows an attacker to take control of the system by sending a malicious request over the internet. This affects versions 22.3 to 26.6 and co...
9.9
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp...
CVE-2026-62452
9.9
Oracle Fusion Middleware: Unauthorized Access to Oracle Internet Directory
CVE-2026-61248
Oracle Fusion Middleware's Oracle Internet Directory is vulnerable to unauthorized access. This means that an attacker with access to the internet directory could take control of it, potentially affec...
9.9
Oracle Hyperion Calculation Manager via HTTP: Takeover Risk
CVE-2026-61206
The Oracle Hyperion Calculation Manager software has a vulnerability that allows an attacker with network access to take control of the system. This could impact not only the Calculation Manager but a...
9.9
Oracle Fusion Middleware: Identity Manager Takeover via Network Access
CVE-2026-61066
Oracle Fusion Middleware's Identity Manager, versions 12.2.1.4.0 and 14.1.2.1.0, have a security flaw that allows a malicious person with network access to take control of the system. This could have ...
9.9
Oracle Fusion Middleware Identity Manager Connector Takeover Risk
CVE-2026-60995
The Oracle Identity Manager Connector, part of Oracle Fusion Middleware, has a security flaw that allows an attacker to take control of the system. This affects versions 12.2.1.4.0 and 14.1.2.1.0. If ...
9.9