CVE-2026-61145
published 2026-07-21CVE-2026-61145: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
38.3th percentile
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | commerce_experience_manager | — | — |
| oracle | commerce_guided_search | — | — |
| oracle_corporation | oracle_commerce_guided_search_oracle_commerce_experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-61145 iv: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
bugzilla·2026-02-23·CVSS 5.0
CVE-2025-61145 [MEDIUM] CVE-2025-61145 iv: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
CVE-2025-61145 iv: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change th
Bugzilla
CVE-2025-61145 libtiff: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
bugzilla·2026-02-23·CVSS 5.0
CVE-2025-61145 [MEDIUM] CVE-2025-61145 libtiff: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
CVE-2025-61145 libtiff: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, chan
Bugzilla
CVE-2025-61145 mingw-libtiff: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
bugzilla·2026-02-23·CVSS 5.0
CVE-2025-61145 [MEDIUM] CVE-2025-61145 mingw-libtiff: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
CVE-2025-61145 mingw-libtiff: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version
Bugzilla
CVE-2025-61145 tkimg: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
bugzilla·2026-02-23·CVSS 5.0
CVE-2025-61145 [MEDIUM] CVE-2025-61145 tkimg: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
CVE-2025-61145 tkimg: libtiff: Denial of service via double free in tiffcrop.c [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change
2026-07-21
Published