Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.81% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 11/7/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks. | |
| Modificada | Crítica (9.3) | 1.3% | — | Barry Voice Assistant Project Barry Voice Assistant | 11/7/2022 | 17/6/2026 | The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mitel Mivoice BusinessMitel Mivoice Business Express | 17/6/2022 | 17/6/2026 | A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A… | |
| Modificada | Media (5.5) | 0.21% | — | Samsung Voice Note | 3/5/2022 | 17/6/2026 | Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities. | |
| Modificada | Media (6.1) | 0.57% | — | Xtendtech Voice Logger | 2/5/2022 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in Xtend Voice Logger 1.0 allows attackers to execute arbitrary web scripts or HTML, via the path of the error page. | |
| Analizada | Crítica (9.8) | 55% | ⚠ Explotación activa | Mitel Mivoice Connect | 26/4/2022 | 6/8/2026 | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA. | |
| Analizada | Crítica (9.8) | 87% | ⚠ Explotación activa💥 Exploit | Mitel MicollabMitel Mivoice Business Express | 10/3/2022 | 17/6/2026 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for… | |
| Modificada | Alta (8.1) | 1.4% | — | Visual Voice Mail Project Visual Voice Mail | 25/2/2022 | 17/6/2026 | The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the AOSP SMS/MMS messaging application.… | |
| Modificada | Media (4.8) | 1.2% | 💥 Exploit | Wpovernight Woocommerce PDF Invoices& Packing Slips | 3/1/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard | |
| Modificada | Alta (7.5) | 0.53% | — | Emuse - Eservices / Envoice Project Emuse - Eservices / Envoice | 29/12/2021 | 17/6/2026 | Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Emuse - Eservices / Envoice Project Emuse - Eservices / Envoice | 29/12/2021 | 17/6/2026 | Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot… | |
| Modificada | Media (5.4) | 0.59% | — | Invoiceninja Invoice Ninja | 24/12/2021 | 17/6/2026 | invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (6.1) | 0.78% | — | Magic-post-voice Project Magic-post-voice | 14/12/2021 | 17/6/2026 | The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.7) | 0.52% | — | Fortinet FortiadcFortinet FortianalyzerFortinet FortimailFortinet Fortimanager+9 | 8/12/2021 | 17/6/2026 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments. | |
| Modificada | Media (4.8) | 0.62% | — | Webventures Client Invoicing BY Sprout Invoices | 17/11/2021 | 17/6/2026 | The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.77% | — | Cisco Unified Customer Voice Portal | 22/7/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input validation of a parameter that is used by the web-based… | |
| Modificada | Media (5.5) | 2.6% | — | Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+32 | 14/7/2021 | 25/8/2026 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR… | |
| Modificada | Media (5.5) | 2.5% | — | Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+28 | 14/7/2021 | 25/8/2026 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Virtualized Voice Browser | 8/7/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Virtualized Voice Browser could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate… | |
| Modificada | Baja (3.3) | 0.24% | — | Samsung Bixby Voice | 11/6/2021 | 17/6/2026 | Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts. | |
| Modificada | Alta (8.1) | 1.8% | — | Invoiceninja Invoice Ninja | 6/6/2021 | 17/6/2026 | In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net… | |
| Modificada | Alta (7.5) | 1.6% | — | Invoiceplane | 17/5/2021 | 29/7/2026 | In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication. | |
| Modificada | Media (5.3) | 1.2% | — | Invoiceplane | 17/5/2021 | 29/7/2026 | InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable. |