Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

499 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.82%—Vocera Report ServerVocera Voice Server25/7/202317/6/2026
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. The filename provided…
ModificadaAlta (7.5)0.54%—Infodrom E-invoice Approval System25/7/202317/6/2026
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.
ModificadaCrítica (9.8)0.63%—Infodrom E-invoice Approval System25/7/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.
ModificadaMedia (6.1)2.2%💥 ExploitSquarepiginteractive Fusioninvoice25/5/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
ModificadaCrítica (9.8)0.92%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce a password change. A successful exploit…
AnalizadaAlta (7.4)0.62%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful exploit could allow an attacker to execute…
ModificadaAlta (7.2)1.7%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.
ModificadaAlta (8.8)0.39%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful…
ModificadaCrítica (9.8)0.99%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
ModificadaMedia (6.1)0.41%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the home.php page. A successful exploit could allow…
ModificadaAlta (7.5)0.87%—Kiwiz Invoices Certification & PDF System Project Kiwiz Invoices Certification & PDF System15/5/202317/6/2026
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
ModificadaMedia (6.1)0.69%—Microsoft Send Customer Voice Survey From Dynamics 36511/4/202317/6/2026
Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability
ModificadaMedia (4.3)0.23%—Wpovernight Woocommerce PDF Invoices& Packing Slips1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
ModificadaMedia (6.1)0.53%—Invoiceplane7/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
ModificadaMedia (5.4)0.62%—Responsivevoice Text TO Speech6/2/202317/6/2026
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.2)0.98%—WEB Invoice Project WEB Invoice2/1/202317/6/2026
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit…
ModificadaAlta (7.2)0.98%—Mohanjith WEB Invoice2/1/202317/6/2026
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit…
ModificadaMedia (5.4)0.54%—Sangoma Voicemail27/12/202217/6/2026
A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to…
ModificadaMedia (6.1)0.54%—Sangoma Voicemail27/12/202217/6/2026
A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 14.0.6.25 is able to address this…
ModificadaMedia (6.1)1.3%💥 ExploitPHP Curl Class Project PHP Curl ClassHT Slider Range FOR Amazon Affiliates Project HT Slider Range FOR Amazon AffiliatesWoo-qiwi-payment-gatewayTeamleader CRM Forms+226/12/202217/6/2026
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
AnalizadaMedia (6.8)11%⚠ Explotación activaMitel Mivoice Connect22/11/202217/6/2026
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
AnalizadaMedia (6.8)11%⚠ Explotación activaMitel Mivoice Connect22/11/202217/6/2026
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
ModificadaCrítica (9.8)0.98%—Pistar Pi-star Digital Voice Dashboard11/11/202217/6/2026
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
ModificadaMedia (6.1)0.67%—Wpovernight Woocommerce PDF Invoices& Packing Slips29/8/202217/6/2026
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.
ModificadaMedia (4.3)0.40%—Fortinet FortiproxyFortinet FortivoiceFortinet FortiosFortinet Fortirecorder Firmware+118/7/202217/6/2026
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2.0.6 and below, 1.2.x, 1.1.x, 1.0.x; FortiVoiceEnterprise 6.4.3…