Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▼ 510 vs. last week
Critical / high1,303▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
–

2,286 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (4.9)0.23%—Fivestarplugins Five Star Business Profile AND SchemaAI10/4/202610/6/2026
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and…
DeferredHigh (7.2)0.24%—Bizessentials Business Essentials FOR Contact Form 7AI10/1/202610/1/2026
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
DeferredHigh (7.6)0.23%—Wptasty Business DirectoryAI9/30/20269/30/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.
DeferredMedium (5.4)0.21%—Business DirectoryAI9/30/20269/30/2026
Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.
DeferredMedium (5.3)0.21%—Connections-pro Connections Business DirectoryAI9/30/20269/30/2026
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including…
DeferredLow (3.5)0.14%—Business Name GeneratorAI9/19/20269/21/2026
The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Awaiting AnalysisHigh (8.8)0.42%—Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI9/15/20269/17/2026
Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract…
Awaiting AnalysisHigh (8.8)0.42%—Oracle Bills OF MaterialAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks…
Awaiting AnalysisHigh (8)0.36%—Oracle Advanced BenefitsAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits.…
Awaiting AnalysisHigh (7.2)0.46%—Oracle ContractsAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this…
Awaiting AnalysisHigh (7.2)0.46%—Oracle E-business SuiteAIOracle ContractsAI9/15/20269/17/2026
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this…
Awaiting AnalysisHigh (8.8)0.42%—Oracle E-business SuiteAIOracle ContractsAI9/15/20269/17/2026
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this…
Awaiting AnalysisHigh (8.1)0.37%—Oracle Mobile Application ServerAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Awaiting AnalysisHigh (7.5)0.24%—Oracle Mobile Application ServerAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the…
Awaiting AnalysisCritical (9.8)0.48%—Oracle Mobile Application ServerAIOracle E-business SuiteAI9/15/20269/16/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Awaiting AnalysisHigh (8.8)0.42%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Awaiting AnalysisHigh (8.8)0.42%—Oracle Document Management AND CollaborationAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document…
Awaiting AnalysisHigh (7.2)0.46%—Oracle Document Management AND CollaborationAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document…
Awaiting AnalysisCritical (9.8)0.48%—Oracle Document Management AND CollaborationAIOracle E-business SuiteAI9/15/20269/16/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document…
Awaiting AnalysisHigh (8.5)0.32%—Oracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. While the…
Awaiting AnalysisHigh (8)0.36%—Oracle Bills OF MaterialAIOracle E-business SuiteAI9/15/20269/17/2026
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the…
Awaiting AnalysisHigh (8.8)0.42%—Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI9/15/20269/17/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex…
DeferredHigh (8.8)0.42%—Oracle E-business SuiteAIOracle Applications ManagerAI9/15/20269/17/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications…
DeferredHigh (7.8)0.14%—Oracle Business Intelligence Enterprise EditionAI9/15/20269/17/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business…
DeferredHigh (8.8)0.42%—Oracle Business Intelligence Enterprise EditionAI9/15/20269/17/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business…