Known Vulnerabilities for Xml Database by Oracle
Listed below are 3 of the newest known vulnerabilities associated with "Xml Database" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71292 json | Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes/classes/ia.base.controller.admin.php, whitelists the `... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71288 json | Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and, for each value, a dynamicall... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71287 json | Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71252 json | toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71241 json | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71238 json | DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an en... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71237 json | Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no s... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71235 json | Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side whe... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71209 json | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against r... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71206 json | Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded clai... | Not Provided | 2026-08-05 | 2026-08-05 |