Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,248 results · page 69 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-60442 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60441 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60438 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-60435 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60429 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-60424 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | CRITICAL 9.0EPSS 0.39% | 21 July 2026 |
| CVE-2026-60422 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | CRITICAL 9.9EPSS 0.39% | 21 July 2026 |
| CVE-2026-60402 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-60389 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 10.0EPSS 0.51% | 21 July 2026 |
| CVE-2026-60388 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60387 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60386 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60385 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60384 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60381 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-60380 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60379 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 10.0EPSS 0.51% | 21 July 2026 |
| CVE-2026-60378 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60377 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.9EPSS 0.39% | 21 July 2026 |
| CVE-2026-60376 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60375 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60374 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60365 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). | CRITICAL 10.0EPSS 0.43% | 21 July 2026 |
| CVE-2026-60364 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60363 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60362 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60361 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-60360 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | CRITICAL 10.0EPSS 0.51% | 21 July 2026 |
| CVE-2026-60358 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 10.0EPSS 0.51% | 21 July 2026 |
| CVE-2026-60355 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60333 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-60329 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60328 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60326 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-60308 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60306 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60302 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60300 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60299 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60298 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60297 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60296 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60294 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60292 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60291 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60290 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60289 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60288 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60287 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-60286 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.