Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

3237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.38%—Persian Woocommerce SMSAI23/7/202623/7/2026
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
AplazadaMedia (5.3)0.31%—Shiptastic FOR WoocommerceAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
AplazadaMedia (4.3)0.25%—Yookassa Yukassa FOR WoocommerceAI23/7/202623/7/2026
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
AplazadaMedia (4.3)0.27%—Product Slider FOR WoocommerceAI23/7/202623/7/2026
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
AplazadaMedia (6.5)0.37%—Multvendorx Woocommerce Product Stock AlertAI23/7/202623/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
AplazadaAlta (7.1)0.25%—Product Enquiry FOR WoocommerceAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
AplazadaMedia (6.5)0.33%—Autopay DLA WoocommerceAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
AplazadaMedia (6.4)0.33%—Grid List View FOR WoocommerceAI23/7/202623/7/2026
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (4.4)0.31%—Berocket Brands FOR WoocommerceAI23/7/202623/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and…
AplazadaMedia (6.4)0.33%—Berocket Brands FOR WoocommerceAI23/7/202623/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaAlta (7.5)0.46%—Lumise Product Designer FOR WoocommerceAI23/7/202623/7/2026
The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping on the user-supplied parameters before…
AnalizadaAlta (7.1)0.39%—Oracle Commerce Guided Search Platform Services21/7/20263/8/2026
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform…
AnalizadaAlta (7.4)0.34%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…
AnalizadaAlta (8.1)0.39%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AnalizadaAlta (7.1)0.16%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…
AnalizadaCrítica (9.8)0.51%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaAlta (8.1)0.42%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (7.5)0.44%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (7.5)0.41%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle…
AnalizadaAlta (7.5)0.41%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AnalizadaCrítica (9.1)0.43%—Oracle Commerce Guided Search Platform Services21/7/20263/8/2026
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search Platform…
AnalizadaCrítica (9.1)0.49%—Oracle Commerce Guided Search Platform Services21/7/20263/8/2026
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform…
AnalizadaCrítica (9.8)0.51%—Oracle Commerce Guided Search Platform Services21/7/20263/8/2026
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform…
AnalizadaCrítica (9.1)0.43%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AnalizadaMedia (5.4)0.23%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…