Vulnerabilities

Summary — last 7 days

New vulnerabilities2,744▼ 71 vs. last week
Critical / high1,416▲ 184 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)106▼ 394 vs. last week
–

32 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (7.5)0.41%—Oracle Scripting8/18/20268/28/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
AnalyzedHigh (7.1)0.30%—Oracle Scripting8/18/20268/28/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
AnalyzedHigh (7.1)0.30%—Oracle Scripting8/18/20268/28/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
AnalyzedHigh (8.8)0.43%—Oracle Scripting8/18/20268/31/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
DeferredMedium (6.5)0.22%—Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI8/13/20268/14/2026
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
AnalyzedMedium (5.4)0.23%—Oracle Scripting7/21/20268/19/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
AnalyzedHigh (8.1)0.39%—Oracle Scripting7/21/20267/31/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
AnalyzedMedium (6.5)0.41%—Oracle Scripting7/21/20267/31/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this…
AnalyzedMedium (6.1)0.24%—Oracle Scripting1/20/20266/17/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human…
AnalyzedMedium (6.1)0.23%—Oracle Scripting10/21/20256/17/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human…
DeferredHigh (8.6)0.54%—Minecraft Integrated ScriptingAI3/13/20256/17/2026
Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated Scripting prior to versions 1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, and 1.19.2-1.0.10 may be vulnerable to arbitrary code execution. By using Java reflection on a…
ModifiedHigh (7.5)0.32%—Hitachienergy Rtu500 Scripting Interface12/19/20236/17/2026
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote…
ModifiedHigh (7.3)0.20%—Codesys Development SystemCodesys Scripting7/28/20236/17/2026
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
ModifiedHigh (8.2)1.2%—Oracle Scripting1/20/20216/17/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful…
ModifiedCritical (9.8)1.7%—Oracle Scripting1/20/20216/17/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks…
ModifiedMedium (6.7)0.42%—HPE Intelligent ProvisioningHPE Service Pack FOR ProliantHPE Smartstart Scripting Toolkit7/30/20206/17/2026
A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the…
ModifiedHigh (8.2)1.3%—Oracle Scripting4/15/20206/17/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks…
ModifiedHigh (8.2)1.3%—Oracle Scripting4/15/20206/17/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human…
ModifiedCritical (9.8)3.4%—Tldp Advanced Bash-scripting Guide5/31/20196/17/2026
The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.
ModifiedHigh (8.2)2.0%—Oracle Scripting7/18/20186/17/2026
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Script Author). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks…
ModifiedCritical (9.8)7.8%—PHPSuse Linux Enterprise Module FOR WEB ScriptingSuse Linux Enterprise Software Development KIT6/8/20176/17/2026
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
ModifiedCritical (9.1)16%—Oracle Scripting4/24/20176/17/2026
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to…
ModifiedHigh (7.5)30%—Novell Suse Linux Enterprise Module FOR WEB ScriptingOpensslNodejs Node.js9/26/20166/17/2026
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
ModifiedMedium (5.9)42%—OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+59/26/20166/17/2026
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
ModifiedHigh (7.5)63%—OpensslNodejs Node.jsNovell Suse Linux Enterprise Module FOR WEB Scripting9/26/20166/17/2026
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.