Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.82% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. The filename provided… | |
| Modificada | Alta (7.5) | 0.54% | — | Infodrom E-invoice Approval System | 25/7/2023 | 17/6/2026 | Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701. | |
| Modificada | Crítica (9.8) | 0.63% | — | Infodrom E-invoice Approval System | 25/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Squarepiginteractive Fusioninvoice | 25/5/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details. | |
| Modificada | Crítica (9.8) | 0.92% | — | Mitel Mivoice Connect | 24/5/2023 | 17/6/2026 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce a password change. A successful exploit… | |
| Analizada | Alta (7.4) | 0.62% | — | Mitel Mivoice Connect | 24/5/2023 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful exploit could allow an attacker to execute… | |
| Modificada | Alta (7.2) | 1.7% | — | Mitel Mivoice Connect | 24/5/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters. | |
| Modificada | Alta (8.8) | 0.39% | — | Mitel Mivoice Connect | 24/5/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful… | |
| Modificada | Crítica (9.8) | 0.99% | — | Mitel Mivoice Connect | 24/5/2023 | 17/6/2026 | A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control. | |
| Modificada | Media (6.1) | 0.41% | — | Mitel Mivoice Connect | 24/5/2023 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the home.php page. A successful exploit could allow… | |
| Modificada | Alta (7.5) | 0.87% | — | Kiwiz Invoices Certification & PDF System Project Kiwiz Invoices Certification & PDF System | 15/5/2023 | 17/6/2026 | The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server) | |
| Modificada | Media (6.1) | 0.69% | — | Microsoft Send Customer Voice Survey From Dynamics 365 | 11/4/2023 | 17/6/2026 | Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | |
| Modificada | Media (4.3) | 0.23% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. | |
| Modificada | Media (6.1) | 0.53% | — | Invoiceplane | 7/2/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php. | |
| Modificada | Media (5.4) | 0.62% | — | Responsivevoice Text TO Speech | 6/2/2023 | 17/6/2026 | The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.2) | 0.98% | — | WEB Invoice Project WEB Invoice | 2/1/2023 | 17/6/2026 | The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit… | |
| Modificada | Alta (7.2) | 0.98% | — | Mohanjith WEB Invoice | 2/1/2023 | 17/6/2026 | The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit… | |
| Modificada | Media (5.4) | 0.54% | — | Sangoma Voicemail | 27/12/2022 | 17/6/2026 | A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to… | |
| Modificada | Media (6.1) | 0.54% | — | Sangoma Voicemail | 27/12/2022 | 17/6/2026 | A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 14.0.6.25 is able to address this… | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | PHP Curl Class Project PHP Curl ClassHT Slider Range FOR Amazon Affiliates Project HT Slider Range FOR Amazon AffiliatesWoo-qiwi-payment-gatewayTeamleader CRM Forms+2 | 26/12/2022 | 17/6/2026 | php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. | |
| Analizada | Media (6.8) | 11% | ⚠ Explotación activa | Mitel Mivoice Connect | 22/11/2022 | 17/6/2026 | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type. | |
| Analizada | Media (6.8) | 11% | ⚠ Explotación activa | Mitel Mivoice Connect | 22/11/2022 | 17/6/2026 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters. | |
| Modificada | Crítica (9.8) | 0.98% | — | Pistar Pi-star Digital Voice Dashboard | 11/11/2022 | 17/6/2026 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. | |
| Modificada | Media (6.1) | 0.67% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 29/8/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (4.3) | 0.40% | — | Fortinet FortiproxyFortinet FortivoiceFortinet FortiosFortinet Fortirecorder Firmware+1 | 18/7/2022 | 17/6/2026 | An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2.0.6 and below, 1.2.x, 1.1.x, 1.0.x; FortiVoiceEnterprise 6.4.3… |