Posts of last 24 hours
A vulnerability has been found in Oracle Commerce Platform 11.4.0 and classified as critical. Impacted is an unknown function of the component Dynamo Application Framework. Performing a manipulation results in improper privilege management.
This vulnerability is known as CVE-2026-61136. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/382036
A vulnerability, which was classified as critical, was found in Oracle Commerce Platform 11.4.0. This issue affects some unknown processing of the component Dynamo Application Framework. Such manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2026-61135. The attack may be launched remotely. There is no exploit available.
https://vuldb.com/vuln/382035
CVE-2026-61134 | Oracle Commerce Platform 11.4.0 Dynamo Application Framework improper authorization
A vulnerability, which was classified as critical, has been found in Oracle Commerce Platform 11.4.0. This vulnerability affects unknown code of the component Dynamo Application Framework. This manipulation causes improper authorization.
This vulnerability appears as CVE-2026-61134. The attack may be initiated remotely. There is no available exploit.
https://vuldb.com/vuln/382034
A vulnerability classified as critical was found in Oracle Commerce Platform 11.4.0. This affects an unknown part of the component Dynamo Application Framework. The manipulation results in Remote Code Execution.
This vulnerability is reported as CVE-2026-61137. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/382033
A vulnerability classified as critical has been found in Oracle Complex Maintenance Repair and Overhaul up to 12.2.15. Affected by this issue is some unknown functionality of the component Internal Operations. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-61138. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/382032
A vulnerability described as critical has been identified in Elastic Kibana up to 8.19.18/9.3.7/9.4.3. Affected by this vulnerability is an unknown functionality of the component Reporting Feature. Executing a manipulation can lead to incomplete blacklist.
This vulnerability is registered as CVE-2026-63142. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/382031
A vulnerability marked as critical has been reported in Netty up to 4.1.135.Final/4.2.15.Final. Affected is an unknown function of the component XmlDecoder. Performing a manipulation results in xml external entity reference.
This vulnerability is cataloged as CVE-2026-56817. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/382030
A vulnerability labeled as problematic has been found in Netty up to 4.1.134.Final/4.2.15.Final. This impacts the function OcspClient.validateResponse of the component OcspClient. Such manipulation leads to improper certificate validation.
This vulnerability is listed as CVE-2026-56820. The attack may be performed from remote. There is no available exploit.
https://vuldb.com/vuln/382029
A vulnerability identified as problematic has been detected in Netty up to 4.2.15.Final/4.1.135.Final. This affects the function Http2Decompressor.decompress of the component Decompression. This manipulation of the argument data causes resource consumption.
This vulnerability is tracked as CVE-2026-56819. The attack is possible to be carried out remotely. No exploit exists.
https://vuldb.com/vuln/382028
A vulnerability categorized as problematic has been discovered in Elastic Kibana up to 9.4.3. The impacted element is an unknown function of the component Scheduled Query. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-63259. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/382027