Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.59% | — | Themehigh Checkout Field Editor FOR Woocommerce | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through 3.6.2. | |
| Modificada | Alta (7.5) | 0.40% | — | Checkmk | 10/6/2024 | 17/6/2026 | Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms. | |
| Modificada | Alta (8.8) | 0.32% | — | Wpdesk Flexible Checkout Fields | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2. | |
| Aplazada | Media (5.3) | 0.20% | — | Claudio Sanches Checkout CieloAI | 4/6/2024 | 17/6/2026 | The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the… | |
| Analizada | Alta (8.1) | 0.48% | — | Checkmk | 29/5/2024 | 17/6/2026 | Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server. | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa💥 Exploit | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Aplazada | Alta (7.5) | 0.52% | — | Tips AND Tricks HQ WP Express CheckoutAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7. | |
| Aplazada | Alta (7.6) | 0.66% | — | Woocommerce ONE Page CheckoutAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0. | |
| Aplazada | Media (5.3) | 0.54% | — | Fmeaddons Conditional Checkout Fields FOR WoocommerceAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3. | |
| Aplazada | Media (4.3) | 0.44% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0. | |
| Aplazada | Alta (7.5) | 0.82% | — | Atutor AcheckerAI | 7/5/2024 | 17/6/2026 | AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Aplazada | Media (5.5) | 0.42% | — | Where DID YOU Hear About US Checkout Field FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via order meta in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop… | |
| Aplazada | Media (5.3) | 0.40% | — | 2checkout Payment Gateway FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to make changes to orders and mark them as… | |
| Analizada | Media (6.7) | 0.16% | — | Checkpoint Harmony Endpoint | 1/5/2024 | 17/6/2026 | A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Mestresdowp Checkout Mestres WPAI | 24/4/2024 | 17/6/2026 | Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7. | |
| Aplazada | Alta (8.2) | 0.56% | — | Mestresdowp Checkout Mestres WPAI | 24/4/2024 | 17/6/2026 | Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7. | |
| Aplazada | Media (4.3) | 0.20% | — | Alumnionline WEB Services LLC WP ADA Compliance Check BasicAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AlumniOnline Web Services LLC WP ADA Compliance Check Basic.This issue affects WP ADA Compliance Check Basic: from n/a through 3.1.3. | |
| Analizada | Crítica (9.8) | 0.52% | — | Checkmk | 24/4/2024 | 17/6/2026 | Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing. | |
| Analizada | Alta (7.3) | 0.15% | — | Checkpoint Identity AgentCheckpoint Zonealarm Extreme Security Nextgen | 18/4/2024 | 17/6/2026 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | |
| Aplazada | Media (6.5) | 0.32% | — | Noorsplugin WP Stripe CheckoutAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 WP Stripe Checkout allows Stored XSS.This issue affects WP Stripe Checkout: from n/a through 1.2.2.41. | |
| Analizada | Media (5.5) | 0.31% | — | Checkmk | 16/4/2024 | 17/6/2026 | Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc | |
| Aplazada | Media (5.4) | 0.20% | — | Jcodex Woocommerce Checkout Field EditorAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jcodex WooCommerce Checkout Field Editor (Checkout Manager).This issue affects WooCommerce Checkout Field Editor (Checkout Manager): from n/a through 2.1.8. | |
| Aplazada | Alta (7.5) | 0.53% | — | Funnelkit CheckoutAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3. | |
| Analizada | Media (5.4) | 0.34% | — | Checkmk | 5/4/2024 | 17/6/2026 | Stored XSS in graph rendering in Checkmk <2.3.0b4. | |
| Aplazada | Media (4.3) | 0.21% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0. |