Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▼ 510 vs. last week
Critical / high1,303▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
2,286 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.9) | 0.23% | — | Fivestarplugins Five Star Business Profile AND SchemaAI | 10/4/2026 | 10/6/2026 | The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and… | |
| Deferred | High (7.2) | 0.24% | — | Bizessentials Business Essentials FOR Contact Form 7AI | 10/1/2026 | 10/1/2026 | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Deferred | High (7.6) | 0.23% | — | Wptasty Business DirectoryAI | 9/30/2026 | 9/30/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27. | |
| Deferred | Medium (5.4) | 0.21% | — | Business DirectoryAI | 9/30/2026 | 9/30/2026 | Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions. | |
| Deferred | Medium (5.3) | 0.21% | — | Connections-pro Connections Business DirectoryAI | 9/30/2026 | 9/30/2026 | The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including… | |
| Deferred | Low (3.5) | 0.14% | — | Business Name GeneratorAI | 9/19/2026 | 9/21/2026 | The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle Bills OF MaterialAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks… | |
| Awaiting Analysis | High (8) | 0.36% | — | Oracle Advanced BenefitsAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits.… | |
| Awaiting Analysis | High (7.2) | 0.46% | — | Oracle ContractsAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Awaiting Analysis | High (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle ContractsAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle ContractsAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Awaiting Analysis | High (8.1) | 0.37% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Awaiting Analysis | High (7.5) | 0.24% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle Document Management AND CollaborationAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document… | |
| Awaiting Analysis | High (7.2) | 0.46% | — | Oracle Document Management AND CollaborationAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Document Management AND CollaborationAIOracle E-business SuiteAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document… | |
| Awaiting Analysis | High (8.5) | 0.32% | — | Oracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. While the… | |
| Awaiting Analysis | High (8) | 0.36% | — | Oracle Bills OF MaterialAIOracle E-business SuiteAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the… | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex… | |
| Deferred | High (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Applications ManagerAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications… | |
| Deferred | High (7.8) | 0.14% | — | Oracle Business Intelligence Enterprise EditionAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business… | |
| Deferred | High (8.8) | 0.42% | — | Oracle Business Intelligence Enterprise EditionAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business… |