SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,248 results · page 68 of 785

CVESummaryPriorityPublished
CVE-2026-61129Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61100Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61097Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common).CRITICAL 9.6EPSS 0.19%21 July 2026
CVE-2026-61076Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-61072Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-61065Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61059Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61041Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60999Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60880Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.8EPSS 0.40%21 July 2026
CVE-2026-60773Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).CRITICAL 9.6EPSS 0.35%21 July 2026
CVE-2026-60719Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API).CRITICAL 9.9EPSS 0.39%21 July 2026
CVE-2026-60711Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60663Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60649Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).CRITICAL 9.1EPSS 0.40%21 July 2026
CVE-2026-60644Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).CRITICAL 10.0EPSS 0.51%21 July 2026
CVE-2026-60632Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).CRITICAL 9.3EPSS 0.35%21 July 2026
CVE-2026-60631Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).CRITICAL 9.3EPSS 0.20%21 July 2026
CVE-2026-60627Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60606Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects).CRITICAL 9.1EPSS 0.40%21 July 2026
CVE-2026-60568Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60567Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-60566Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60565Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).CRITICAL 9.9EPSS 0.40%21 July 2026
CVE-2026-60564Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).CRITICAL 9.6EPSS 0.34%21 July 2026
CVE-2026-60562Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60561Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60555Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60552Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60551Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).CRITICAL 9.8EPSS 0.47%21 July 2026
CVE-2026-60547Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60542Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60541Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60540Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).CRITICAL 9.6EPSS 0.34%21 July 2026
CVE-2026-60538Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60537Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60535Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60532Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60531Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60524Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60463Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60461Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60460Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60459Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60458Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60457Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60456Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60447Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-60446Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60445Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.43%21 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.