Vulnerabilities

Summary — last 7 days

New vulnerabilities2,772▲ 13 vs. last week
Critical / high1,288▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

119 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.2)1.3%—Oracle Complex Maintenance, Repair, AND OverhaulOracle Complex Maintenance Repair AND Overhaul1/20/20216/17/2026
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex…
ModifiedHigh (8.2)1.3%—Oracle Complex Maintenance, Repair, AND OverhaulOracle Complex Maintenance Repair AND Overhaul1/20/20216/17/2026
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex…
ModifiedHigh (8.2)1.3%—Oracle Complex Maintenance, Repair, AND OverhaulOracle Complex Maintenance Repair AND Overhaul1/20/20216/17/2026
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair7/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedHigh (8.2)1.3%—Oracle Depot Repair4/15/20206/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful…
ModifiedCritical (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+593/10/20206/17/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModifiedHigh (8.2)1.4%—Oracle Complex Maintenance Repair AND Overhaul4/21/20166/17/2026
Unspecified vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul component in Oracle Supply Chain Products Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Dialog Box.
ModifiedMedium (5.4)0.27%—Gcspublishing Home Repair9/9/20146/17/2026
The Home Repair (aka com.gcspublishing.houserepairtalk) application 3.7.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedHigh (7.2)4.0%—Consona Dynamic AgentConsona Repair ManagerConsona Subscriber ActivationConsona Subscriber Agent5/12/20106/16/2026
tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the…
ModifiedMedium (6.8)1.1%—Realitymedias Repairshop25/7/20106/16/2026
SQL injection vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prod parameter in a products.details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModifiedLow (2.6)1.5%💥 ExploitRealitymedias Repairshop25/7/20106/16/2026
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.
ModifiedHigh (10)5.4%💥 ExploitDaniel Stenberg Dispair12/31/20026/16/2026
Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.
Orbitaley — Vulnerabilities