Known Vulnerabilities for Vm Server by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Vm Server" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57535 json | Content injected to PDF rendering contexts could, in many places, include HTML content including |
Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-57522 json | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), whi... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-57521 json | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access ... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-57520 json | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with Ma... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-57303 json | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allow... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57300 json | A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read perm... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57289 json | Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname va... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-56968 json | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could resu... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56779 json | MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows au... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-56771 json | NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authe... | Not Provided | 2026-06-25 | 2026-06-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Oracle | Vm Server | 3.6 | |||
| Application | Oracle | Vm Server | 3.4 | |||
| Operating System | Oracle | Vm Server | 3.4 | |||
| Application | Oracle | Vm Server | 3.4 | |||
| Application | Oracle | Vm Server | 3.3 | |||
| Application | Oracle | Vm Server | 3.3 | |||
| Application | Oracle | Vm Server | 3.2 | |||
| Operating System | Oracle | Vm Server | 3.2 | |||
| Operating System | Oracle | Vm Server | 3.1 |