Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.57% | — | Invoiceplane | 16/12/2024 | 17/6/2026 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.56% | — | Invoiceplane | 16/12/2024 | 17/6/2026 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.1) | 0.35% | — | Linknacional Invoice Payment FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in linknacional Invoice Payment for WooCommerce invoice-payment-for-woocommerce allows Reflected XSS.This issue affects Invoice Payment for WooCommerce: from n/a through <= 1.7.2. | |
| Modificada | Media (6.5) | 0.60% | — | Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2. | |
| Aplazada | Media (5.3) | 0.49% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0. | |
| Aplazada | Media (6.1) | 0.43% | — | PDF Invoices AND Packing Slips Generator FOR WoocommerceAI | 23/11/2024 | 17/6/2026 | The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (4.6) | 0.21% | — | Samsung Voice Recorder | 6/11/2024 | 17/6/2026 | Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen. | |
| Aplazada | Media (5.3) | 0.41% | — | Wpovernight Woocommerce PDF Invoices Packing SlipsAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 3.8.6. | |
| Analizada | Alta (8.8) | 1.3% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insufficient parameter sanitization. A successful exploit could allow… | |
| Analizada | Media (5.6) | 0.77% | 💥 PoC | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary… | |
| Analizada | Crítica (9.8) | 1.8% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and… | |
| Aplazada | Media (6.5) | 0.27% | — | Pepro DEV Group Pepro Ultimate InvoiceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice pepro-ultimate-invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through <= 2.0.6. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Transsion AivoiceassistantAI | 16/10/2024 | 17/6/2026 | Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component. | |
| Analizada | Media (5.3) | 0.41% | — | Oretnom23 Simple Invoice Generator System | 7/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql… | |
| Analizada | Crítica (9.8) | 0.46% | — | Propovoice | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Propovoice Propovoice Pro allows SQL Injection.This issue affects Propovoice Pro: from n/a through 1.7.0.3. | |
| Analizada | Media (6.9) | 0.52% | — | Opentext Cx-e Voice | 22/8/2024 | 3/9/2026 | Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system. | |
| Aplazada | Media (5.3) | 0.34% | — | Propovoice CRMAI | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4. | |
| Modificada | Alta (8.8) | 0.49% | — | Mitel Mivoice Mx-one | 13/8/2024 | 17/6/2026 | The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema. | |
| Modificada | Media (4.8) | 0.40% | — | Expert Invoice Project Expert Invoice | 18/6/2024 | 17/6/2026 | The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.32% | — | Slicedinvoices Sliced Invoices | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2. | |
| Analizada | Alta (7.2) | 0.64% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1. | |
| Modificada | Alta (7.1) | 0.85% | — | Fortinet Fortivoice | 14/5/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests. | |
| Aplazada | Alta (7.1) | 0.44% | — | Propovoice CRMAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Propovoice Propovoice CRM allows Stored XSS.This issue affects Propovoice CRM: from n/a through 1.7.6.2. | |
| Aplazada | Media (4.3) | 0.34% | — | Tychesoftwares Print Invoice AND Delivery Notes FOR WoocommerceAITychesoftwares Arconix ShortcodesAITychesoftwares Arconix FAQAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ:… | |
| Modificada | Alta (7.2) | 0.40% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 2/5/2024 | 17/6/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be… |