Vulnerabilities
Summary — last 7 days
New vulnerabilities2,766▲ 12 vs. last week
Critical / high1,276▼ 252 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
119 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 4/13/2026 | 6/17/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/repairs/manage_repair.php. | |
| Analyzed | Low (2.7) | 0.32% | — | Oretnom23 Computer AND Mobile Repair Shop Management System | 4/13/2026 | 6/17/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/admin/services/view_service.php. | |
| Modified | Low (2.7) | 0.32% | — | Oretnom23 Computer AND Mobile Repair Shop Management System | 4/13/2026 | 6/17/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php. | |
| Deferred | Medium (5.3) | 0.33% | — | Ateeq Rafeeq RepairbuddyAI | 4/8/2026 | 7/24/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through <= 4.1132. | |
| Deferred | Medium (5.3) | 0.41% | — | RepairbuddyAI | 3/21/2026 | 6/17/2026 | The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to modify admin-level plugin settings. First, the wc_rb_get_fresh_nonce() function… | |
| Deferred | Medium (4.3) | 0.13% | — | Font Pairing Preview FOR Landing PagesAI | 3/7/2026 | 6/17/2026 | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing… | |
| Deferred | High (8.1) | 0.49% | — | Axiomthemes AU Pair AgencyAI | 3/5/2026 | 6/17/2026 | Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through <= 1.2.2. | |
| Deferred | Medium (4.3) | 0.23% | — | RepairbuddyAI | 1/17/2026 | 6/17/2026 | The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for authenticated attackers,… | |
| Analyzed | Critical (9.4) | 3.0% | — | Wondershare Repairit | 9/17/2025 | 9/25/2026 | Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissions granted to an… | |
| Analyzed | Critical (9.1) | 2.8% | — | Wondershare Repairit | 9/17/2025 | 9/25/2026 | Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissions… | |
| Deferred | Medium (5.4) | 0.13% | — | Hack Repair GUY Plugin ArchiverAI | 9/17/2025 | 9/25/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the bulk_remove() function. This makes it possible for unauthenticated attackers to arbitrary directory… | |
| Deferred | High (7.2) | 0.73% | — | Hack Repair GUY Plugin ArchiverAI | 9/12/2025 | 6/17/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the prepare_items function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Deferred | Medium (5.4) | 0.25% | — | Smartdatasoft CAR Repair ServicesAI | 6/6/2025 | 6/17/2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services car-repair-services allows Server Side Request Forgery.This issue affects Car Repair Services: from n/a through <= 5.0. | |
| Deferred | Medium (4.3) | 0.25% | — | Ateeq Rafeeq RepairbuddyAI | 4/4/2025 | 6/17/2026 | Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RepairBuddy: from n/a through <= 3.8213. | |
| Modified | Medium (5.5) | 0.60% | — | Oretnom23 AC Repair AND Services System | 3/23/2025 | 6/17/2026 | A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public… | |
| Analyzed | Medium (6.9) | 0.56% | — | Oretnom23 AC Repair AND Services System | 3/23/2025 | 6/17/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/services/manage_service.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Deferred | Medium (6.9) | 0.48% | — | Viames Pair FrameworkAI | 3/17/2025 | 6/17/2026 | A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The manipulation of the argument cookieName leads to deserialization. The attack can be… | |
| Deferred | High (8.8) | 0.44% | — | Ateeq Rafeeq RepairbuddyAI | 12/31/2024 | 6/17/2026 | Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Privilege Escalation.This issue affects RepairBuddy: from n/a through <= 3.8119. | |
| Deferred | High (8.8) | 0.53% | — | RepairbuddyAI | 12/18/2024 | 6/17/2026 | The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX action. This makes… | |
| Modified | Critical (9.8) | 1.8% | 💥 PoC | Webfulcreations Computer Repair Shop | 11/11/2024 | 6/17/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115. | |
| Analyzed | Medium (6.1) | 0.37% | — | Oracle Complex Maintenance Repair AND Overhaul | 4/16/2024 | 6/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Analyzed | Medium (6.1) | 0.36% | — | Oracle Complex Maintenance Repair AND Overhaul | 4/16/2024 | 6/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Modified | Medium (6.1) | 0.18% | — | Oracle Complex Maintenance Repair AND Overhaul | 4/16/2024 | 6/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Analyzed | Medium (6.1) | 0.20% | — | Oracle Complex Maintenance Repair AND Overhaul | 4/16/2024 | 6/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Analyzed | Medium (6.1) | 0.35% | — | Oracle Complex Maintenance Repair AND Overhaul | 4/16/2024 | 6/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… |