Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3271 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Yaad Sarig Payment Gateway FOR WCAI | 7/10/2026 | 7/10/2026 | The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers. | |
| Pendiente de análisis | Media (5.1) | 0.48% | — | PinggatewayAI | 6/10/2026 | 6/10/2026 | An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later). | |
| Aplazada | Alta (7.1) | 0.15% | — | Tomlister Payflex Payment GatewayAI | 6/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | |
| Aplazada | Media (5.3) | 0.14% | — | Deema Payment GatewayAI | 6/10/2026 | 6/10/2026 | The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken. | |
| Aplazada | Media (5.3) | 0.14% | — | Deema Payment GatewayAI | 6/10/2026 | 6/10/2026 | The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order. | |
| Aplazada | Alta (7.5) | 0.28% | — | Insumermodel Mppx Condition GateAIInsumermodel Mppx Token GateAI | 5/10/2026 | 6/10/2026 | mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain… | |
| Aplazada | Media (5.3) | 0.18% | — | UPI QR Code Payment GatewayAI | 5/10/2026 | 6/10/2026 | The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. | |
| Analizada | Alta (8.7) | 0.59% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 4/10/2026 | 5/10/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28. | |
| Pendiente de análisis | Crítica (9.9) | 0.94% | 💥 PoC | Gitlab AI GatewayAI | 2/10/2026 | 2/10/2026 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template… | |
| Aplazada | Media (5.3) | 0.18% | — | Paytm Payment GatewayAI | 2/10/2026 | 2/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders,… | |
| Aplazada | Alta (7.5) | 0.18% | — | Paytm Payment GatewayAI | 1/10/2026 | 1/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection… | |
| Aplazada | Alta (7.5) | 0.22% | — | Paytm Payment GatewayAI | 1/10/2026 | 1/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts… | |
| Aplazada | Alta (7.5) | 0.37% | — | Comelit Multi User GatewayAI | 1/10/2026 | 5/10/2026 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a… | |
| Aplazada | Alta (8.8) | 0.25% | — | Comelit Multi User GatewayAI | 1/10/2026 | 5/10/2026 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password. | |
| En análisis | Crítica (9.4) | 0.24% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is… | |
| En análisis | Media (5.3) | 0.36% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service. | |
| En análisis | Media (6.5) | 0.26% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither… | |
| En análisis | Media (6.6) | 0.41% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and… | |
| En análisis | Alta (7.2) | 0.39% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code… | |
| En análisis | Alta (7.2) | 0.39% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account. | |
| En análisis | Alta (7.5) | 0.21% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to… | |
| En análisis | Alta (7) | 0.19% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including… | |
| En análisis | Alta (7.2) | 0.64% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account. | |
| En análisis | Alta (7.2) | 0.47% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an… | |
| En análisis | Crítica (9.1) | 0.37% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account… |