Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-60166: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. in Oracle Corporation Oracle Java SECVE-2026-60166
0

CVE-2026-60166 is a vulnerability in Oracle Java SE 8u491 affecting the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially gain unauthorized read access to some data accessible by Oracle Java SE. Exploitation is difficult and requires human interaction from a person other than the attacker. This vulnerability primarily affects client-side Java deployments running untrusted code in sandboxed environments, such as Java Web Start applications or applets. Server-side Java deployments running only trusted code are not affected. The CVSS 3.1 base score is 3.1, indicating a low severity impact focused on confidentiality. No official patch or remediation level is currently specified by Oracle. Oracle recommends applying security patches promptly but has not explicitly confirmed a fix for this specific vulnerability in the provided advisory.

Join the discussion
CVE-2026-60164: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. in Oracle Corporation Oracle Java SECVE-2026-60164
0

CVE-2026-60164 is a low-severity vulnerability in Oracle Java SE 8u491 affecting the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially gain unauthorized read access to some data accessible by Oracle Java SE. Exploitation is difficult and requires human interaction from a person other than the attacker. This vulnerability primarily affects client-side Java deployments running sandboxed Java Web Start applications or applets that load untrusted code. Server-side deployments running only trusted code are not affected. The CVSS 3.1 base score is 3.1, reflecting limited confidentiality impact without integrity or availability effects. Oracle has not explicitly stated a patch or fix for this specific vulnerability in the provided advisory, but recommends applying Critical Patch Updates promptly.

Join the discussion
CVE-2026-60147: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM fCVE-2026-60147
0

CVE-2026-60147 is a vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting multiple specified versions. It allows an unauthenticated attacker with network access via multiple protocols to gain unauthorized read and write access to some accessible data. The vulnerability involves the Security component and can be exploited through APIs, including web services and sandboxed Java applications that run untrusted code. The CVSS 3.1 base score is 6.5, indicating a medium severity level. No official patch or remediation level is confirmed in the advisory, and no known exploits in the wild have been reported. Oracle strongly recommends applying security patches promptly as part of their Critical Patch Update process.

Join the discussion
CVE-2026-47063: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. in Oracle Corporation Oracle Java SECVE-2026-47063
0

CVE-2026-47063 is a high-severity vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting multiple specified versions. It allows an unauthenticated attacker with network access via multiple protocols to compromise the affected products by unauthorized creation, deletion, or modification of critical data. The vulnerability arises from issues in the Libraries component and can be exploited through APIs, including web services and sandboxed Java applications running untrusted code. The CVSS 3.1 base score is 7.5, indicating a high impact on integrity without affecting confidentiality or availability. Oracle has published a Critical Patch Update advisory addressing multiple vulnerabilities but does not explicitly confirm patch availability for this specific CVE in the provided data.

Join the discussion
CVE-2026-47058: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. in Oracle Corporation Oracle Java SECVE-2026-47058
0

CVE-2026-47058 is a vulnerability in Oracle Java SE's Scripting component affecting versions 8u491, 8u491-perf, and 11.0.31. It allows an unauthenticated attacker with network access via multiple protocols to potentially compromise the product. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, or unauthorized access to all data accessible by Oracle Java SE. The vulnerability involves the use of APIs in the Scripting component and applies to Java deployments running sandboxed Java Web Start applications or applets that load untrusted code. The CVSS 3.1 base score is 7.4, indicating high severity with confidentiality and integrity impacts. Patch status is not confirmed in the advisory, so users should consult Oracle's official security alerts for updates.

Join the discussion
CVE-2026-47057: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. in Oracle Corporation Oracle Java SECVE-2026-47057
0

CVE-2026-47057 is a high-severity vulnerability in Oracle Java SE's Scripting component affecting versions 8u491, 8u491-perf, and 11.0.31. It allows an unauthenticated attacker with network access via multiple protocols to cause a denial of service by hanging or crashing the Java SE environment. The vulnerability can be exploited through APIs, including those used by sandboxed Java Web Start applications or applets that run untrusted code. The CVSS 3.1 base score is 7.5, reflecting a significant availability impact without confidentiality or integrity loss. No official patch or remediation level is currently confirmed in the vendor advisory. Oracle recommends applying security patches promptly and staying on actively supported versions. The vendor advisory linked does not explicitly confirm patch availability for this specific vulnerability yet.

Join the discussion
CVE-2026-47035: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. in Oracle Corporation Oracle Java SECVE-2026-47035
0

CVE-2026-47035 is a low-severity vulnerability in Oracle Java SE 8u491 affecting the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially compromise the product, but exploitation is difficult and requires human interaction from someone other than the attacker. Successful exploitation can lead to unauthorized update, insert, or delete access to some data accessible by Oracle Java SE. This vulnerability primarily affects client-side Java deployments running sandboxed Java Web Start applications or applets that load untrusted code. Server-side deployments running only trusted code are not affected. The CVSS 3.1 base score is 3.1, indicating low impact on integrity with no confidentiality or availability impact. Oracle has not explicitly stated a patch or fix for this vulnerability in the provided advisory.

Join the discussion
CVE-2026-47034: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. in Oracle Corporation Oracle Java SECVE-2026-47034
0

CVE-2026-47034 is a vulnerability in Oracle Java SE 8u491, specifically in the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially compromise the product. Exploitation requires human interaction from a user other than the attacker. Successful exploitation can lead to unauthorized update, insert, or delete access to some data accessible by Oracle Java SE. This vulnerability primarily affects client-side Java deployments running sandboxed Java Web Start applications or applets with untrusted code. It does not affect server-side deployments running only trusted code. The CVSS 3.1 base score is 3.1, indicating low severity with integrity impact only. No official patch or remediation level is currently confirmed by Oracle for this specific vulnerability.

Join the discussion
CVE-2026-47030: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. in Oracle Corporation Oracle Java SECVE-2026-47030
0

CVE-2026-47030 is a low-severity vulnerability in Oracle Java SE 8u491, specifically in the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to potentially compromise the product. Exploitation requires human interaction from a person other than the attacker. Successful exploitation can lead to unauthorized update, insert, or delete access to some data accessible by Oracle Java SE. This vulnerability primarily affects client-side Java deployments running sandboxed Java Web Start applications or applets that load untrusted code. Server-side deployments running only trusted code are not affected.

Join the discussion
CVE-2026-47021: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. in Oracle Corporation Oracle Java SECVE-2026-47021
0

CVE-2026-47021 is a vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting the 2D component. It allows an unauthenticated attacker with network access via multiple protocols to cause a partial denial of service. The vulnerability can be exploited through APIs, including web services supplying data to these APIs, and affects Java deployments running untrusted code in sandboxed environments. The CVSS 3.1 base score is 5.3, indicating a medium severity level.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Package: pkg:maven/com.oracle.java/java-se
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses