Aggregator
CVE-2025-30762 | Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 Core information disclosure
1 month 1 week ago
A vulnerability, which was classified as problematic, has been found in Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0. This issue affects some unknown processing of the component Core. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2025-30762. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30760 | Oracle JD Edwards EnterpriseOne Tools up to 9.2.9.3 Web Runtime SEC improper authorization
1 month 1 week ago
A vulnerability classified as critical was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.9.3. This vulnerability affects unknown code of the component Web Runtime SEC. The manipulation leads to improper authorization.
This vulnerability was named CVE-2025-30760. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50073 | Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 Web Container Remote Code Execution
1 month 1 week ago
A vulnerability classified as critical has been found in Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0. This affects an unknown part of the component Web Container. The manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2025-50073. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50065 | Oracle GraalVM for JDK 24.0.1 Native Image denial of service
1 month 1 week ago
A vulnerability was found in Oracle GraalVM for JDK 24.0.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Native Image. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2025-50065. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50064 | Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 Core improper authorization
1 month 1 week ago
A vulnerability was found in Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Core. The manipulation leads to improper authorization.
This vulnerability is known as CVE-2025-50064. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50069 | Oracle Database Server up to 19.27/21.18 improper authorization
1 month 1 week ago
A vulnerability was found in Oracle Database Server up to 19.27/21.18. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2025-50069. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50062 | Oracle PeopleSoft Enterprise HCM Global Payroll Core 9.2.51/9.2.52 Global Payroll for Core improper authorization
1 month 1 week ago
A vulnerability was found in Oracle PeopleSoft Enterprise HCM Global Payroll Core 9.2.51/9.2.52 and classified as critical. This issue affects some unknown processing of the component Global Payroll for Core. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2025-50062. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30753 | Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 Core improper authorization
1 month 1 week ago
A vulnerability has been found in Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 and classified as critical. This vulnerability affects unknown code of the component Core. The manipulation leads to improper authorization.
This vulnerability was named CVE-2025-30753. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50059 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition Networking Remote Code Execution (Nessus ID 242142)
1 month 1 week ago
A vulnerability, which was classified as critical, was found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition. This affects an unknown part of the component Networking. The manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2025-50059. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50106 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition 2D Remote Code Execution (Nessus ID 242142)
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition. Affected by this issue is some unknown functionality of the component 2D. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2025-50106. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30754 | Oracle Java SE up to 24.0.1 JSSE Remote Code Execution (Nessus ID 242142)
1 month 1 week ago
A vulnerability classified as critical was found in Oracle Java SE up to 24.0.1. Affected by this vulnerability is an unknown functionality of the component JSSE. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2025-30754. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30752 | Oracle Java SE/GraalVM for JDK Compiler denial of service
1 month 1 week ago
A vulnerability classified as problematic has been found in Oracle Java SE and GraalVM for JDK. Affected is an unknown function of the component Compiler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-30752. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Lessons Learned From McDonald's Big AI Flub
1 month 1 week ago
McDonald's hiring platform was using its original default credentials and inadvertently exposed information belonging to possibly millions of job applicants.
Alexander Culafi
CVE-2025-49829 | cyberark conjur authorization
1 month 1 week ago
A vulnerability was found in cyberark conjur. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-49829. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49828 | cyberark conjur API Endpoint special elements used in a template engine
1 month 1 week ago
A vulnerability was found in cyberark conjur. It has been declared as critical. This vulnerability affects unknown code of the component API Endpoint. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability was named CVE-2025-49828. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30746 | Oracle iStore up to 12.2.14 Shopping Cart Remote Code Execution
1 month 1 week ago
A vulnerability was found in Oracle iStore up to 12.2.14. It has been classified as critical. This affects an unknown part of the component Shopping Cart. The manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2025-30746. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30745 | Oracle MES for Process Manufacturing 12.2.12/12.2.13 Device Integration cross-site request forgery
1 month 1 week ago
A vulnerability was found in Oracle MES for Process Manufacturing 12.2.12/12.2.13 and classified as critical. Affected by this issue is some unknown functionality of the component Device Integration. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-30745. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30747 | Oracle PeopleSoft Enterprise PeopleTools 8.60/8.61/8.62 PIA Core Technology Remote Code Execution
1 month 1 week ago
A vulnerability has been found in Oracle PeopleSoft Enterprise PeopleTools 8.60/8.61/8.62 and classified as critical. Affected by this vulnerability is an unknown functionality of the component PIA Core Technology. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2025-30747. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30744 | Oracle Mobile Field Service up to 12.2.13 Multiplatform Sync Errors improper authorization
1 month 1 week ago
A vulnerability, which was classified as critical, was found in Oracle Mobile Field Service up to 12.2.13. Affected is an unknown function of the component Multiplatform Sync Errors. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2025-30744. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com