Vulnerabilities
Summary — last 7 days
New vulnerabilities2,771▼ 1 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 211 vs. last week
119 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.1) | 0.22% | — | Webfulcreations RepairbuddyAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226. | |
| Deferred | Medium (6.5) | 0.17% | — | Webfulcreations RepairbuddyAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225. | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex… | |
| Deferred | High (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of… | |
| Deferred | High (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 9/15/2026 | 9/17/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of… | |
| Awaiting Analysis | High (8.5) | 0.40% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 9/15/2026 | 9/22/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Deferred | High (7.8) | 0.84% | — | Tubitak Bilgem Pardus Boot RepairAI | 9/11/2026 | 9/11/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8. | |
| Deferred | High (7.5) | 0.58% | — | RepairbuddyAI | 9/10/2026 | 9/10/2026 | Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. | |
| Analyzed | High (8) | 0.59% | — | Microsoft VM Repair | 9/8/2026 | 9/14/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network. | |
| Deferred | High (7.8) | 0.49% | — | Tubitak Bilgem Pardus Boot RepairAI | 8/31/2026 | 9/1/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8. | |
| Deferred | Medium (5.3) | 0.29% | — | RepairbuddyAI | 8/24/2026 | 8/24/2026 | Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions. | |
| Analyzed | High (7.2) | 0.49% | — | Oracle Complex Maintenance Repair AND Overhaul | 8/18/2026 | 8/27/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analyzed | High (7.1) | 0.29% | — | Oracle Complex Maintenance Repair AND Overhaul | 8/18/2026 | 8/31/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Deferred | Medium (5.5) | 0.43% | — | Sourcecodester Computer Repair Shop Management SystemAI | 8/6/2026 | 8/12/2026 | A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analyzed | High (7.5) | 0.28% | — | Oracle Complex Maintenance Repair AND Overhaul | 7/21/2026 | 8/19/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex… | |
| Analyzed | Medium (5.4) | 0.23% | — | Oracle Complex Maintenance Repair AND Overhaul | 7/21/2026 | 8/3/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Deferred | High (7.1) | 0.24% | — | Auto RepairAI | 6/17/2026 | 6/17/2026 | Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions. | |
| Analyzed | High (7.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analyzed | High (7.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analyzed | High (8.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Deferred | Medium (6.5) | 0.34% | — | RepairbuddyAI | 6/15/2026 | 6/17/2026 | Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions. | |
| Deferred | Medium (5.5) | 0.27% | — | Sourcecodester Computer Repair Shop Management SystemAI | 6/1/2026 | 7/22/2026 | A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be… | |
| Deferred | Medium (4.3) | 0.22% | — | Webfulcreations RepairbuddyAI | 5/26/2026 | 7/24/2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121. | |
| Deferred | Low (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 4/13/2026 | 6/17/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php | |
| Deferred | Low (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 4/13/2026 | 6/17/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/admin/repairs/view_details.php. |