Вторник обновлений
апрель 2026 г.
Во второй вторник месяца Microsoft, Adobe, SAP, Siemens и Schneider Electric публикуют пакетно; Oracle — в третий вторник января, апреля, июля и октября. Здесь записи того дня из нашей базы, по баллу действия: сначала KEV и зрелые эксплойты.
Как считается: метка CNA + дата публикации (окно два дня, UTC). Полного соответствия бюллетеню производителя не утверждается; внеплановые обновления выходят в другие дни.
записей: 331 · KEV: 4
Затрагивают ваш стек
Записи этого месяца, совпадающие с продуктами и версиями вашего стека.
Войдите, чтобы увидеть совпадения со стеком; записи и уведомления бесплатны. →
Microsoft · 14 апреля
163 · KEV: 4 · критических: 2| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
69На этой неделе | CVE-2026-32201Готовый эксплойт | Microsoft SharePoint Server Spoofing Vulnerabilitymicrosoft · sharepoint server · CWE-20 | Средняя6,5 | KEV | 43,4 % | 14 апр. 2026 г. |
69На этой неделе | CVE-2026-33824Готовый эксплойт | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-415 | Критическая9,8 | KEV | 1,6 % | 14 апр. 2026 г. |
61На этой неделе | CVE-2026-33825Готовый эксплойт | Microsoft Defender Elevation of Privilege Vulnerabilitymicrosoft · defender antimalware platform · CWE-1220 | Высокая7,8 | KEV | 0,4 % | 14 апр. 2026 г. |
48В плане | CVE-2026-32202Готовый эксплойт | Windows Shell Spoofing Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Средняя4,3 | KEV | 4,9 % | 14 апр. 2026 г. |
36Наблюдать | CVE-2026-26149Эксплойта нет | Microsoft Power Apps Desktop Client Spoofing Vulnerabilitymicrosoft · power apps · CWE-150 | Критическая9,0 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2026-26178Эксплойта нет | Windows Advanced Rasterization Platform Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-190 | Высокая8,8 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2026-32157Эксплойта нет | Remote Desktop Client Remote Code Execution Vulnerabilitymicrosoft · remote desktop client · CWE-416 | Высокая8,8 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2026-32171Эксплойта нет | Azure Logic Apps Elevation of Privilege Vulnerabilitymicrosoft · azure logic apps · CWE-522 | Высокая8,8 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2026-32225Эксплойта нет | Windows Shell Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Высокая8,8 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2026-33120Эксплойта нет | Microsoft SQL Server Remote Code Execution Vulnerabilitymicrosoft · sql server 2016 · CWE-822 | Высокая8,8 | — | 0,9 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-27928Эксплойта нет | Windows Hello Security Feature Bypass Vulnerabilitymicrosoft · windows server 2016 · CWE-20 | Высокая8,7 | — | 0,7 % | 14 апр. 2026 г. |
33Наблюдать | CVE-2026-32162Эксплойта нет | Windows COM Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-349 | Высокая8,4 | — | 0,2 % | 14 апр. 2026 г. |
- CVE-2026-3220169На этой неделе
Microsoft SharePoint Server Spoofing Vulnerability
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 43 %microsoft · sharepoint server14 апр. 2026 г.
- CVE-2026-3382469На этой неделе
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 2 %microsoft · windows 10 160714 апр. 2026 г.
- CVE-2026-3382561На этой неделе
Microsoft Defender Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %microsoft · defender antimalware platform14 апр. 2026 г.
- CVE-2026-3220248В плане
Windows Shell Spoofing Vulnerability
СредняяCVSS 4,3KEVГотовый эксплойтEPSS 5 %microsoft · windows 10 160714 апр. 2026 г.
- CVE-2026-2614936Наблюдать
Microsoft Power Apps Desktop Client Spoofing Vulnerability
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %microsoft · power apps14 апр. 2026 г.
- CVE-2026-2617835Наблюдать
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · windows 10 160714 апр. 2026 г.
- CVE-2026-3215735Наблюдать
Remote Desktop Client Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · remote desktop client14 апр. 2026 г.
- CVE-2026-3217135Наблюдать
Azure Logic Apps Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · azure logic apps14 апр. 2026 г.
- CVE-2026-3222535Наблюдать
Windows Shell Security Feature Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · windows 10 160714 апр. 2026 г.
- CVE-2026-3312035Наблюдать
Microsoft SQL Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · sql server 201614 апр. 2026 г.
- CVE-2026-2792834Наблюдать
Windows Hello Security Feature Bypass Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %microsoft · windows server 201614 апр. 2026 г.
- CVE-2026-3216233Наблюдать
Windows COM Elevation of Privilege Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %microsoft · windows 10 180914 апр. 2026 г.
+151 ещёВсе записи производителя
Adobe · 14 апреля
53 · KEV: 0 · критических: 6| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-27303Эксплойта нет | Adobe Connect | Deserialization of Untrusted Data (CWE-502)adobe · connect · CWE-502 | Критическая9,6 | — | 1,9 % | 14 апр. 2026 г. |
38Наблюдать | CVE-2026-34615Эксплойта нет | Adobe Connect | Deserialization of Untrusted Data (CWE-502)adobe · connect · CWE-502 | Критическая9,3 | — | 1,8 % | 14 апр. 2026 г. |
37Наблюдать | CVE-2026-27243Эксплойта нет | Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)adobe · connect · CWE-79 | Критическая9,3 | — | 0,7 % | 14 апр. 2026 г. |
37Наблюдать | CVE-2026-27245Эксплойта нет | Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)adobe · connect · CWE-79 | Критическая9,3 | — | 0,7 % | 14 апр. 2026 г. |
37Наблюдать | CVE-2026-27246Эксплойта нет | Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)adobe · connect · CWE-79 | Критическая9,3 | — | 0,7 % | 14 апр. 2026 г. |
37Наблюдать | CVE-2026-27304Эксплойта нет | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Критическая9,3 | — | 0,5 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-27290Эксплойта нет | Adobe Framemaker | Untrusted Search Path (CWE-426)adobe · framemaker · CWE-426 | Высокая8,6 | — | 0,3 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-27305Эксплойта нет | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · coldfusion · CWE-22 | Высокая8,6 | — | 1,0 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-34617Эксплойта нет | Adobe Connect | Cross-site Scripting (XSS) (CWE-79)adobe · connect · CWE-79 | Высокая8,7 | — | 0,7 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-34622Эксплойта нет | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)adobe · acrobat · CWE-1321 | Высокая8,6 | — | 0,7 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-34632Эксплойта нет | Photoshop Installer | CWE-427: Uncontrolled Search Path Elementadobe · photoshop installer · CWE-427 | Высокая8,6 | — | 0,3 % | 15 апр. 2026 г. |
33Наблюдать | CVE-2026-27306Эксплойта нет | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Высокая8,4 | — | 0,5 % | 14 апр. 2026 г. |
- CVE-2026-2730339Наблюдать
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %adobe · connect14 апр. 2026 г.
- CVE-2026-3461538Наблюдать
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %adobe · connect14 апр. 2026 г.
- CVE-2026-2724337Наблюдать
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %adobe · connect14 апр. 2026 г.
- CVE-2026-2724537Наблюдать
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %adobe · connect14 апр. 2026 г.
- CVE-2026-2724637Наблюдать
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %adobe · connect14 апр. 2026 г.
- CVE-2026-2730437Наблюдать
ColdFusion | Improper Input Validation (CWE-20)
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %adobe · coldfusion14 апр. 2026 г.
- CVE-2026-2729034Наблюдать
Adobe Framemaker | Untrusted Search Path (CWE-426)
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %adobe · framemaker14 апр. 2026 г.
- CVE-2026-2730534Наблюдать
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %adobe · coldfusion14 апр. 2026 г.
- CVE-2026-3461734Наблюдать
Adobe Connect | Cross-site Scripting (XSS) (CWE-79)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %adobe · connect14 апр. 2026 г.
- CVE-2026-3462234Наблюдать
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %adobe · acrobat14 апр. 2026 г.
- CVE-2026-3463234Наблюдать
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %adobe · photoshop installer15 апр. 2026 г.
- CVE-2026-2730633Наблюдать
ColdFusion | Improper Input Validation (CWE-20)
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %adobe · coldfusion14 апр. 2026 г.
+41 ещёВсе записи производителя
SAP · 14 апреля
0 · KEV: 0 · критических: 0В этом окне записей нет.
Siemens · 14 апреля
5 · KEV: 0 · критических: 0| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-25654Эксплойта нет | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3).siemens · sinec nms · CWE-639 | Высокая8,7 | — | 0,5 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2026-27668Эксплойта нет | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8).siemens · ruggedcom crossbow secure access manager primary (sam-p) · CWE-266 | Высокая8,7 | — | 0,4 % | 14 апр. 2026 г. |
27Наблюдать | CVE-2026-24032Эксплойта нет | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC).siemens · sinec nms · CWE-347 | Средняя6,9 | — | 0,3 % | 14 апр. 2026 г. |
25Наблюдать | CVE-2025-40745Эксплойта нет | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcentesiemens · simcenter 3d · CWE-295 | Средняя6,3 | — | 0,1 % | 14 апр. 2026 г. |
20Наблюдать | CVE-2026-33892Эксплойта нет | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Prosiemens · industrial edge management pro v1 · CWE-305 | Средняя5,1 | — | 0,4 % | 14 апр. 2026 г. |
- CVE-2026-2565434Наблюдать
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3).
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %siemens · sinec nms14 апр. 2026 г.
- CVE-2026-2766834Наблюдать
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8).
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %siemens · ruggedcom crossbow secure access manager primary (sam-p)14 апр. 2026 г.
- CVE-2026-2403227Наблюдать
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC).
СредняяCVSS 6,9Эксплойта нетEPSS 0 %siemens · sinec nms14 апр. 2026 г.
- CVE-2025-4074525Наблюдать
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcente
СредняяCVSS 6,3Эксплойта нетEPSS 0 %siemens · simcenter 3d14 апр. 2026 г.
- CVE-2026-3389220Наблюдать
A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro
СредняяCVSS 5,1Эксплойта нетEPSS 0 %siemens · industrial edge management pro v114 апр. 2026 г.
Schneider Electric · 14 апреля
8 · KEV: 0 · критических: 0| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
27Наблюдать | CVE-2026-2399Эксплойта нет | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files oschneider-electric · powerchute serial shutdown · CWE-22 | Средняя6,9 | — | 0,2 % | 14 апр. 2026 г. |
27Наблюдать | CVE-2026-2402Эксплойта нет | CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the usschneider-electric · powerchute serial shutdown · CWE-307 | Средняя6,9 | — | 0,3 % | 14 апр. 2026 г. |
27Наблюдать | CVE-2026-2404Эксплойта нет | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters tschneider-electric · powerchute serial shutdown · CWE-116 | Средняя6,9 | — | 0,2 % | 14 апр. 2026 г. |
27Наблюдать | CVE-2026-4832Эксплойта нет | CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauschneider electric · easergy micom p14x · CWE-798 | Средняя6,9 | — | 0,4 % | 14 апр. 2026 г. |
21Наблюдать | CVE-2026-2400Эксплойта нет | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reschneider-electric · powerchute serial shutdown · CWE-93 | Средняя5,3 | — | 0,2 % | 14 апр. 2026 г. |
21Наблюдать | CVE-2026-2403Эксплойта нет | CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting loschneider-electric · powerchute serial shutdown · CWE-1284 | Средняя5,3 | — | 0,2 % | 14 апр. 2026 г. |
21Наблюдать | CVE-2026-2405Эксплойта нет | CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of seschneider-electric · powerchute serial shutdown · CWE-400 | Средняя5,3 | — | 0,2 % | 14 апр. 2026 г. |
9Наблюдать | CVE-2026-2401Эксплойта нет | CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when schneider-electric · powerchute serial shutdown · CWE-532 | Низкая2,4 | — | 0,1 % | 14 апр. 2026 г. |
- CVE-2026-239927Наблюдать
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files o
СредняяCVSS 6,9Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
- CVE-2026-240227Наблюдать
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the us
СредняяCVSS 6,9Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
- CVE-2026-240427Наблюдать
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters t
СредняяCVSS 6,9Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
- CVE-2026-483227Наблюдать
CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unau
СредняяCVSS 6,9Эксплойта нетEPSS 0 %schneider electric · easergy micom p14x14 апр. 2026 г.
- CVE-2026-240021Наблюдать
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to re
СредняяCVSS 5,3Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
- CVE-2026-240321Наблюдать
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting lo
СредняяCVSS 5,3Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
- CVE-2026-240521Наблюдать
CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of se
СредняяCVSS 5,3Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
- CVE-2026-24019Наблюдать
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when
НизкаяCVSS 2,4Эксплойта нетEPSS 0 %schneider-electric · powerchute serial shutdown14 апр. 2026 г.
Oracle (Critical Patch Update) · 21 апреля
102 · KEV: 0 · критических: 5| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-34275Эксплойта нет | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration).oracle · advanced inbound telephony · CWE-306 | Критическая9,8 | — | 0,5 % | 21 апр. 2026 г. |
36Наблюдать | CVE-2026-34279Эксплойта нет | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).oracle · enterprise manager base platform · CWE-306 | Критическая9,1 | — | 0,5 % | 21 апр. 2026 г. |
36Наблюдать | CVE-2026-34285Эксплойта нет | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).oracle · identity manager connector · CWE-306 | Критическая9,1 | — | 0,4 % | 21 апр. 2026 г. |
36Наблюдать | CVE-2026-34286Эксплойта нет | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).oracle · identity manager connector · CWE-306 | Критическая9,1 | — | 0,4 % | 21 апр. 2026 г. |
36Наблюдать | CVE-2026-34287Эксплойта нет | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).oracle · identity manager connector · CWE-284 | Критическая9,1 | — | 0,4 % | 21 апр. 2026 г. |
34Наблюдать | CVE-2026-21997Эксплойта нет | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core).oracle · life sciences empirica signal · CWE-284 | Высокая8,5 | — | 0,2 % | 21 апр. 2026 г. |
34Наблюдать | CVE-2026-34291Эксплойта нет | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).oracle · http server · CWE-284 | Высокая8,7 | — | 0,3 % | 21 апр. 2026 г. |
32Наблюдать | CVE-2026-34309Эксплойта нет | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).oracle · peoplesoft enterprise peopletools · CWE-284 | Высокая8,1 | — | 0,4 % | 21 апр. 2026 г. |
31Наблюдать | CVE-2026-35243Эксплойта нет | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).oracle · application development framework · CWE-284 | Высокая7,8 | — | 0,2 % | 21 апр. 2026 г. |
30Наблюдать | CVE-2026-22010Proof of concept | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comoracle · financial services analytical applications infrastructure · CWE-284 | Высокая7,5 | — | 0,3 % | 21 апр. 2026 г. |
30Наблюдать | CVE-2026-22011Proof of concept | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).oracle · applications dba · CWE-284 | Высокая7,6 | — | 0,3 % | 21 апр. 2026 г. |
30Наблюдать | CVE-2026-22016Proof of concept | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).oracle · jre · CWE-200 | Высокая7,5 | — | 0,7 % | 21 апр. 2026 г. |
- CVE-2026-3427539Наблюдать
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oracle · advanced inbound telephony21 апр. 2026 г.
- CVE-2026-3427936Наблюдать
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %oracle · enterprise manager base platform21 апр. 2026 г.
- CVE-2026-3428536Наблюдать
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %oracle · identity manager connector21 апр. 2026 г.
- CVE-2026-3428636Наблюдать
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %oracle · identity manager connector21 апр. 2026 г.
- CVE-2026-3428736Наблюдать
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %oracle · identity manager connector21 апр. 2026 г.
- CVE-2026-2199734Наблюдать
Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core).
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %oracle · life sciences empirica signal21 апр. 2026 г.
- CVE-2026-3429134Наблюдать
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %oracle · http server21 апр. 2026 г.
- CVE-2026-3430932Наблюдать
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %oracle · peoplesoft enterprise peopletools21 апр. 2026 г.
- CVE-2026-3524331Наблюдать
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %oracle · application development framework21 апр. 2026 г.
- CVE-2026-2201030Наблюдать
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (com
ВысокаяCVSS 7,5Proof of conceptEPSS 0 %oracle · financial services analytical applications infrastructure21 апр. 2026 г.
- CVE-2026-2201130Наблюдать
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).
ВысокаяCVSS 7,6Proof of conceptEPSS 0 %oracle · applications dba21 апр. 2026 г.
- CVE-2026-2201630Наблюдать
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %oracle · jre21 апр. 2026 г.
+90 ещёВсе записи производителя