Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-34343

Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2012 R2, Windows Server 2022, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-34342

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2016, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2012, Windows Server 2022, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-34341

Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2012, Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-34340

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 version 23H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 11 version 26H1, Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-34339

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows 10 Version 1809, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34338

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2016, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 23H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-34337

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2022, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2016, Windows Server 2025, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-34335

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 11 Version 23H2, Windows Server 2012, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-34334

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2022, Windows 11 version 26H1, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows Server 2012, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 23H2, Windows 11 Version 25H2, Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-34333

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 version 26H1, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2012, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
2

CVE-2026-34332

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-34331

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2022, Windows 10 Version 22H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 11 version 26H1, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-34330

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows 11 Version 23H2, Windows Server 2012 R2, Windows 11 version 23H2, Windows Server 2019, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2016
Provider severity
HIGH
Conflicts
2

CVE-2026-3433

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_updated websocket event broadcasts to members of the affected team or channel which allows an authenticated attacker with guest-level access to observe permission scheme change notifications for private teams they are not a member of via the websocket connection.. Mattermost Advisory ID: MMSA-2026-00616

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34329

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2022, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-34328

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34327

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Partner Center
Provider severity
HIGH
Conflicts
0

CVE-2026-34325

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Analytical Applications Infrastructure executes to compromise Oracle Financial Services Analytical Applications Infrastructure. Succ

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Financial Services Analytical Applications Infrastructure
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34324

Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Life Sciences InForm accessible data as well as unauthorized

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Life Sciences InForm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34323

Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or d

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Life Sciences InForm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34321

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker. Su

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Financial Services Analytical Applications Infrastructure
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34320

Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.1.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Customer Screening. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Financial Services Customer Screening
Provider severity
HIGH
Conflicts
1

CVE-2026-3432

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.

PUBLISHED
Vendor
SimStudioAI
Product
sim
Provider severity
CRITICAL
Conflicts
0

CVE-2026-34319

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a h

PUBLISHED
Vendor
Oracle Corporation
Product
MySQL Shell
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34318

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized acce

PUBLISHED
Vendor
Oracle Corporation
Product
MySQL Shell
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34317

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a h

PUBLISHED
Vendor
Oracle Corporation
Product
MySQL Shell
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34316

Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact addition

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Commerce Service Center
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34315

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, del

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle WebLogic Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34314

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized creation, deletion or m

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Financial Services Analytical Applications Infrastructure
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34313

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data o

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Financial Services Analytical Applications Infrastructure
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34312

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Access Method privilege with network access via multiple protocols to compromise RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of RDBMS accessible data. CVSS 3.1 Base

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Database Server
Provider severity
LOW
Conflicts
1

CVE-2026-34311

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Hospitality OPERA 5 Property Services
Provider severity
CRITICAL
Conflicts
1

CVE-2026-34310

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Financial Services Analytical Applications Infrastructure
Provider severity
HIGH
Conflicts
1

CVE-2026-3431

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.

PUBLISHED
Vendor
SimStudioAI
Product
sim
Provider severity
CRITICAL
Conflicts
0

CVE-2026-34309

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise PeopleTools
Provider severity
HIGH
Conflicts
1

CVE-2026-34308

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability

PUBLISHED
Vendor
Oracle Corporation
Product
MySQL Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34307

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional p

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise PeopleTools
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34306

Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Project Costing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Project Costing accessible data. CVSS 3.

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Project Costing
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34305

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle WebLogic Server
Provider severity
HIGH
Conflicts
1

CVE-2026-34304

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impac

PUBLISHED
Vendor
Oracle Corporation
Product
MySQL Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34303

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availabi

PUBLISHED
Vendor
Oracle Corporation
Product
MySQL Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34302

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in Oracle Workflow, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete acc

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Workflow
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34301

Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Maintenance Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Maintenance M

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Maintenance Management
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34300

Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Contracts accessible data. CVSS 3.1 Base Score 6.5

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Contracts
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34299

Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Maintenance Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Maintenance M

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Maintenance Management
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34298

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized rea

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Applications Framework
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34297

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Common Architecture accessible data. CVSS 3.1 Ba

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle HCM Common Architecture
Provider severity
HIGH
Conflicts
1

CVE-2026-34296

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile Product Lifecycle Management f

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Agile Product Lifecycle Management for Process
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34295

Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score

PUBLISHED
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise SCM Purchasing
Provider severity
MEDIUM
Conflicts
1