Vulnerabilities

Summary — last 7 days

New vulnerabilities2,771▼ 1 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 211 vs. last week
–

119 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.22%—Webfulcreations RepairbuddyAI10/5/202610/6/2026
Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226.
DeferredMedium (6.5)0.17%—Webfulcreations RepairbuddyAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225.
Awaiting AnalysisHigh (8.8)0.42%—Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI9/15/20269/17/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex…
DeferredHigh (8.8)0.42%—Oracle E-business SuiteAIOracle Depot RepairAI9/15/20269/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of…
DeferredHigh (7.2)0.46%—Oracle E-business SuiteAIOracle Depot RepairAI9/15/20269/17/2026
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of…
Awaiting AnalysisHigh (8.5)0.40%—Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI9/15/20269/22/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
DeferredHigh (7.8)0.84%—Tubitak Bilgem Pardus Boot RepairAI9/11/20269/11/2026
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.
DeferredHigh (7.5)0.58%—RepairbuddyAI9/10/20269/10/2026
Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
AnalyzedHigh (8)0.59%—Microsoft VM Repair9/8/20269/14/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
DeferredHigh (7.8)0.49%—Tubitak Bilgem Pardus Boot RepairAI8/31/20269/1/2026
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
DeferredMedium (5.3)0.29%—RepairbuddyAI8/24/20268/24/2026
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
AnalyzedHigh (7.2)0.49%—Oracle Complex Maintenance Repair AND Overhaul8/18/20268/27/2026
Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.…
AnalyzedHigh (7.1)0.29%—Oracle Complex Maintenance Repair AND Overhaul8/18/20268/31/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
DeferredMedium (5.5)0.43%—Sourcecodester Computer Repair Shop Management SystemAI8/6/20268/12/2026
A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The…
AnalyzedHigh (7.5)0.28%—Oracle Complex Maintenance Repair AND Overhaul7/21/20268/19/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex…
AnalyzedMedium (5.4)0.23%—Oracle Complex Maintenance Repair AND Overhaul7/21/20268/3/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
DeferredHigh (7.1)0.24%—Auto RepairAI6/17/20266/17/2026
Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.
AnalyzedHigh (7.5)0.33%—Oracle Complex Maintenance Repair AND Overhaul6/17/20266/18/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
AnalyzedHigh (7.5)0.33%—Oracle Complex Maintenance Repair AND Overhaul6/17/20266/18/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
AnalyzedHigh (8.5)0.33%—Oracle Complex Maintenance Repair AND Overhaul6/17/20266/18/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
DeferredMedium (6.5)0.34%—RepairbuddyAI6/15/20266/17/2026
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
DeferredMedium (5.5)0.27%—Sourcecodester Computer Repair Shop Management SystemAI6/1/20267/22/2026
A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…
DeferredMedium (4.3)0.22%—Webfulcreations RepairbuddyAI5/26/20267/24/2026
Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.
DeferredLow (2.7)0.31%—Sourcecodester Computer AND Mobile Repair Shop Management SystemAI4/13/20266/17/2026
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php
DeferredLow (2.7)0.31%—Sourcecodester Computer AND Mobile Repair Shop Management SystemAI4/13/20266/17/2026
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/admin/repairs/view_details.php.
Orbitaley — Vulnerabilities