Known Vulnerabilities for HM Portfolio by Matthew Haines-Young
Listed below are 10 of the newest known vulnerabilities associated with "HM Portfolio" by "Matthew Haines-Young".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-60988 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60987 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60986 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60985 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60984 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-59709 json | Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when pr... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-59708 json | The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-57712 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-49069 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-46962 json | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). ... | Not Provided | 2026-06-17 | 2026-06-17 |