Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.50% | — | Fortinet FortimailFortinet FortiddosFortinet FortivoiceFortinet Fortirecorder+1 | 28/3/2025 | 17/6/2026 | An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0,… | |
| Aplazada | Media (4.3) | 0.28% | — | Creativewerkdesigns Export Order Product Customer Coupon FOR Woocommerce TO Google SheetsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets wpsyncsheets-woocommerce.This issue affects Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets: from n/a through <= 1.8.2. | |
| Analizada | Media (5.1) | 0.40% | — | Oretnom23 Food Ordering Management System | 27/3/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Food Ordering Management System up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menus/view_menu.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (4.7) | 0.46% | — | Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1. | |
| Aplazada | Crítica (9.8) | 0.77% | — | Webtoffee Export ALL Posts Products Orders Refunds UsersAI | 27/3/2025 | 17/6/2026 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP… | |
| Aplazada | Alta (7.5) | 0.41% | — | Audi Universal Traffic RecorderAI | 25/3/2025 | 17/6/2026 | An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by occupying the only available connection. The… | |
| Aplazada | Media (4.3) | 0.18% | — | Flipdish Ordering SystemAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in flipdish Flipdish Ordering System flipdish-ordering-system allows Cross Site Request Forgery.This issue affects Flipdish Ordering System: from n/a through <= 1.5.2. | |
| Aplazada | Baja (2.1) | 0.18% | — | Audi Universal Traffic Recorder APPAI | 20/3/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unknown function of the component FTP Credentials. The manipulation leads to use of hard-coded password. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability… | |
| Analizada | Media (6.5) | 0.39% | — | Webtoffee Order Export & Order Import FOR Woocommerce | 20/3/2025 | 17/6/2026 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to… | |
| Analizada | Media (6.5) | 0.39% | — | Webtoffee Order Export & Order Import FOR Woocommerce | 20/3/2025 | 17/6/2026 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Analizada | Alta (7.2) | 0.71% | — | Webtoffee Order Export & Order Import FOR Woocommerce | 20/3/2025 | 17/6/2026 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Media (4.9) | 0.74% | — | Webtoffee Order Export & Order Import FOR Woocommerce | 20/3/2025 | 17/6/2026 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log… | |
| Analizada | Media (6.9) | 0.53% | — | Oretnom23 Online Food Ordering System | 17/3/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.22% | — | Spring Devs PRE Order Addon FOR WoocommerceAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spring Devs Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin wc-pre-order allows Reflected XSS.This issue affects Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin: from n/a through <=… | |
| Aplazada | Media (4.3) | 0.40% | — | HCL Appscan Traffic RecorderAI | 13/3/2025 | 17/6/2026 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the application is running. | |
| Aplazada | Alta (7.5) | 0.56% | — | Nitin Prakash WC Place Order Without PaymentAIPHPAI | 10/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment wc-place-order-without-payment allows PHP Local File Inclusion.This issue affects WC Place Order Without Payment: from n/a through <= 2.6.7. | |
| Analizada | Alta (7.5) | 0.52% | — | Cozyvision SMS Alert Order Notifications | 3/3/2025 | 26/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.7.8. | |
| Analizada | Media (6.1) | 0.33% | — | Cozyvision SMS Alert Order Notifications | 3/3/2025 | 26/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Reflected XSS.This issue affects SMS Alert Order Notifications: from n/a through <= 3.7.8. | |
| Analizada | Alta (7.5) | 0.47% | — | Directsoftware Order Attachments FOR Woocommerce | 28/2/2025 | 17/6/2026 | The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which… | |
| Aplazada | Media (4.3) | 0.31% | — | Xfinitysoft Order Limit FOR WoocommerceAI | 25/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Xfinitysoft Order Limit for WooCommerce wc-order-limit-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Limit for WooCommerce: from n/a through <= 3.0.2. | |
| Aplazada | Alta (7.1) | 0.31% | — | Matt Brooks Library Instruction RecorderAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Brooks Library Instruction Recorder library-instruction-recorder allows Reflected XSS.This issue affects Library Instruction Recorder: from n/a through <= 1.1.4. | |
| Analizada | Alta (7.5) | 0.50% | — | Smackcoders Export ALL Posts, Products, Orders, Refunds & Users | 12/2/2025 | 17/6/2026 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Analizada | Alta (7.5) | 0.16% | — | Audiocodes Mediant Session Border Controller | 7/2/2025 | 17/6/2026 | An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords. | |
| Aplazada | Media (5.9) | 0.47% | — | Jem-products Order Export FOR WoocommerceAI | 31/1/2025 | 17/6/2026 | The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can… | |
| Modificada | Media (5.4) | 0.30% | — | Visualmodo Borderless | 31/1/2025 | 17/6/2026 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… |