Vulnerabilities
Summary — last 7 days
New vulnerabilities2,744▼ 71 vs. last week
Critical / high1,416▲ 184 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)106▼ 394 vs. last week
32 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (7.5) | 0.41% | — | Oracle Scripting | 8/18/2026 | 8/28/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analyzed | High (7.1) | 0.30% | — | Oracle Scripting | 8/18/2026 | 8/28/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analyzed | High (7.1) | 0.30% | — | Oracle Scripting | 8/18/2026 | 8/28/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analyzed | High (8.8) | 0.43% | — | Oracle Scripting | 8/18/2026 | 8/31/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Deferred | Medium (6.5) | 0.22% | — | Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI | 8/13/2026 | 8/14/2026 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| Analyzed | Medium (5.4) | 0.23% | — | Oracle Scripting | 7/21/2026 | 8/19/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analyzed | High (8.1) | 0.39% | — | Oracle Scripting | 7/21/2026 | 7/31/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analyzed | Medium (6.5) | 0.41% | — | Oracle Scripting | 7/21/2026 | 7/31/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analyzed | Medium (6.1) | 0.24% | — | Oracle Scripting | 1/20/2026 | 6/17/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human… | |
| Analyzed | Medium (6.1) | 0.23% | — | Oracle Scripting | 10/21/2025 | 6/17/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human… | |
| Deferred | High (8.6) | 0.54% | — | Minecraft Integrated ScriptingAI | 3/13/2025 | 6/17/2026 | Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated Scripting prior to versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, and 1.19.2-1.0.10 may be vulnerable to arbitrary code execution. By using Java reflection on a… | |
| Modified | High (7.5) | 0.32% | — | Hitachienergy Rtu500 Scripting Interface | 12/19/2023 | 6/17/2026 | A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote… | |
| Modified | High (7.3) | 0.20% | — | Codesys Development SystemCodesys Scripting | 7/28/2023 | 6/17/2026 | In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users. | |
| Modified | High (8.2) | 1.2% | — | Oracle Scripting | 1/20/2021 | 6/17/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful… | |
| Modified | Critical (9.8) | 1.7% | — | Oracle Scripting | 1/20/2021 | 6/17/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks… | |
| Modified | Medium (6.7) | 0.42% | — | HPE Intelligent ProvisioningHPE Service Pack FOR ProliantHPE Smartstart Scripting Toolkit | 7/30/2020 | 6/17/2026 | A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the… | |
| Modified | High (8.2) | 1.3% | — | Oracle Scripting | 4/15/2020 | 6/17/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks… | |
| Modified | High (8.2) | 1.3% | — | Oracle Scripting | 4/15/2020 | 6/17/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human… | |
| Modified | Critical (9.8) | 3.4% | — | Tldp Advanced Bash-scripting Guide | 5/31/2019 | 6/17/2026 | The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo. | |
| Modified | High (8.2) | 2.0% | — | Oracle Scripting | 7/18/2018 | 6/17/2026 | Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Script Author). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks… | |
| Modified | Critical (9.8) | 7.8% | — | PHPSuse Linux Enterprise Module FOR WEB ScriptingSuse Linux Enterprise Software Development KIT | 6/8/2017 | 6/17/2026 | /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833. | |
| Modified | Critical (9.1) | 16% | — | Oracle Scripting | 4/24/2017 | 6/17/2026 | Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modified | High (7.5) | 30% | — | Novell Suse Linux Enterprise Module FOR WEB ScriptingOpensslNodejs Node.js | 9/26/2016 | 6/17/2026 | crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation. | |
| Modified | Medium (5.9) | 42% | — | OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+5 | 9/26/2016 | 6/17/2026 | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | |
| Modified | High (7.5) | 63% | — | OpensslNodejs Node.jsNovell Suse Linux Enterprise Module FOR WEB Scripting | 9/26/2016 | 6/17/2026 | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. |