Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.75% | — | Oretnom23 Simple Invoice Generator System | 10/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issue affects some unknown processing of the file login.php. The manipulation of the argument cashier leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed… | |
| Modificada | Baja (2.4) | 0.30% | — | Samsung Voice Recorder | 5/12/2023 | 17/6/2026 | Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen. | |
| Modificada | Media (4.1) | 1.1% | — | Microsoft Send Customer Voice Survey From Dynamics 365 | 14/11/2023 | 17/6/2026 | Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | |
| Modificada | Alta (7.5) | 0.45% | — | Samsung Bixby Voice | 7/11/2023 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege. | |
| Modificada | Alta (7.5) | 0.45% | — | E-invoice Project E-invoice | 27/10/2023 | 17/6/2026 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting. This issue affects E-invoice: before 2.1. | |
| Modificada | Media (6.1) | 0.33% | — | Rednao Woocommerce PDF Invoice Builder | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <= 1.2.102 versions. | |
| Modificada | Media (6.1) | 0.54% | — | Mozilla Common Voice | 4/10/2023 | 17/6/2026 | Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for training voice recognition-related tools. Version 1.88.2 is vulnerable to reflected Cross-Site Scripting given that user-controlled data flows to a path expression (path of a… | |
| Modificada | Media (4.3) | 0.28% | — | Mitel Mivoice Connect | 14/9/2023 | 17/6/2026 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL,… | |
| Modificada | Media (4.3) | 0.54% | — | Rednao Woocommerce PDF Invoice Builder | 31/8/2023 | 17/6/2026 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice… | |
| Modificada | Media (4.3) | 0.31% | — | Rednao Woocommerce PDF Invoice Builder | 31/8/2023 | 17/6/2026 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the SaveCustomField function in versions up to, and including, 1.2.90. This makes it possible for unauthenticated attackers to create invoice fields provided they can trick an admin into… | |
| Modificada | Media (4.8) | 0.49% | — | Rednao Woocommerce PDF Invoice Builder | 31/8/2023 | 17/6/2026 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.90 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Modificada | Media (4.3) | 0.29% | — | Rednao Woocommerce PDF Invoice Builder | 31/8/2023 | 17/6/2026 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request… | |
| Modificada | Alta (8.8) | 0.80% | — | Rednao Woocommerce PDF Invoice Builder | 31/8/2023 | 17/6/2026 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for subscribers or… | |
| Modificada | Media (4.9) | 0.56% | — | Mitel Mivoice Connect | 25/8/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information. | |
| Modificada | Media (4.9) | 0.56% | — | Mitel Mivoice Connect | 25/8/2023 | 17/6/2026 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information. | |
| Modificada | Alta (7.5) | 0.59% | — | Mitel Mivoice Connect | 25/8/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information. | |
| Modificada | Media (5.5) | 0.61% | — | Mitel Mivoice Connect | 25/8/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an… | |
| Modificada | Media (5.5) | 0.61% | — | Mitel Mivoice Connect | 25/8/2023 | 17/6/2026 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an… | |
| Modificada | Crítica (9.8) | 1.7% | — | Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware | 14/8/2023 | 17/6/2026 | A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system. | |
| Modificada | Crítica (9.8) | 0.63% | — | Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware | 14/8/2023 | 17/6/2026 | A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations. | |
| Modificada | Crítica (9.8) | 0.90% | — | Mitel Mivoice Connect | 14/8/2023 | 17/6/2026 | The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control. | |
| Modificada | Alta (7.5) | 0.63% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. During the unzip operation, the… | |
| Modificada | Alta (7.5) | 0.56% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and… | |
| Modificada | Media (6.5) | 0.58% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user has the ability to modify these entries… | |
| Modificada | Alta (7.5) | 0.49% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Arbitrary File Upload. The BaseController class, that each of the service controllers derives from, allows for the upload of arbitrary files. If the HTTP request is a multipart/form-data POST request, any parameters with a… |