Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.42% | — | Infosoftplugin Woocommerce Sales MIS ReportAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in infosoftplugin WooCommerce Sales MIS Report woocommerce-mis-report allows Reflected XSS.This issue affects WooCommerce Sales MIS Report: from n/a through <= 4.0.3. | |
| Aplazada | Crítica (9.3) | 0.54% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.1. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Salesmate Add-on FOR Gravity FormsAIGravityforms Gravity FormsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows SQL Injection.This issue affects Salesmate Add-On for Gravity Forms: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.1) | 0.31% | — | Saleswonder Team Wp2leadsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.5. | |
| Aplazada | Media (5.3) | 0.42% | — | Salesmate Add-on FOR Gravity FormsAIGravityforms Gravity FormsAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Salesmate Add-On for Gravity Forms: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.1) | 0.37% | — | Devrix DX Sales CRMAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevriX DX Sales CRM dx-sales-crm allows Reflected XSS.This issue affects DX Sales CRM: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Anzar Ahmed NI NI Woocommerce Sales Report EmailAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Sales Report Email ni-woocommerce-sales-report-email allows Reflected XSS.This issue affects Ni WooCommerce Sales Report Email: from n/a through <= 3.1.4. | |
| Aplazada | Alta (7.1) | 0.31% | — | Rusalex Wordpress-to-candidate FOR Salesforce CRMAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RusAlex WordPress-to-candidate for Salesforce CRM salesforce-wordpress-to-candidate allows Reflected XSS.This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 0.70% | — | Zankover Fami Sales PopupAI | 7/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami Sales Popup fami-sales-popup allows PHP Local File Inclusion.This issue affects Fami Sales Popup: from n/a through <= 2.0.0. | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft Dynamics 365 Sales | 6/2/2025 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (4.3) | 0.24% | — | NI Sales Commission FOR WoocommerceAI | 31/1/2025 | 17/6/2026 | The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the… | |
| Aplazada | Alta (7.1) | 0.26% | — | Saleswonder Team Wp2leadsAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.2. | |
| Analizada | Alta (8.1) | 0.56% | — | Salesagility Suitecrm | 7/1/2025 | 17/6/2026 | An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database. | |
| Analizada | Alta (8.8) | 1.1% | — | Salesagility Suitecrm | 7/1/2025 | 17/6/2026 | An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution. | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 4/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/update_account.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.3) | 0.52% | — | Code-projects Point OF Sales AND Inventory Management System | 4/1/2025 | 17/6/2026 | A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /user/search_num.php. The manipulation of the argument search leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management System 1.0. Affected is an unknown function of the file /user/minus_cart.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/search_result.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.3) | 0.45% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/add_cart.php. The manipulation of the argument id/qty leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.43% | — | Code-projects Point OF Sales AND Inventory Management System | 3/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /user/search_result2.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. It is possible to… | |
| Aplazada | Media (6.4) | 0.38% | — | Surbma Salesautopilot ShortcodeAI | 12/12/2024 | 17/6/2026 | The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sa-form' shortcode in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.43% | — | NI Woocommerce Sales ReportAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Sales Report ni-woocommerce-sales-report allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ni WooCommerce Sales Report: from n/a through <= 3.7.3. |