Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Webbax Winbizpayment | 12/6/2023 | 17/6/2026 | Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php. | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Media (6.5) | 0.42% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible… | |
| Modificada | Media (5.4) | 0.76% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | El plugin Event Registration Calendar By vcita, versiones hasta la 3.9.1 inlcusive, y el plugin Online Payments – Get Paid with PayPal, Square & Stripe, para WordPress son vulnerables a Cross-Site Scripting almacenado a través del parámetro "email" en versiones hasta la 1.3.1 inclusive, debido a un insuficiente… | |
| Modificada | Crítica (9.8) | 0.90% | — | Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | |
| Modificada | Media (4.8) | 0.47% | — | Fullworksplugins Quick Paypal Payments | 2/5/2023 | 17/6/2026 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 0.37% | — | IBM Safer Payments | 28/4/2023 | 17/6/2026 | IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 249192. | |
| Modificada | Media (5.3) | 0.65% | — | IBM Safer Payments | 28/4/2023 | 17/6/2026 | IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6.1.0.05, and 6.2.0.00 through 6.2.1.00 could allow an authenticated attacker under special circumstances to send multiple specially crafted API requests that could cause the application to crash. IBM… | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Safer Payments | 28/4/2023 | 17/6/2026 | IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02 and 6.5.0.00 does not properly allocate resources without limits or throttling which could allow a remote attacker to cause a denial of service. IBM X-Force ID: 249190. | |
| Modificada | Media (5.4) | 0.36% | — | Fullworksplugins Quick Paypal Payments | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.6) | 0.38% | — | Oracle Banking Payments | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Book/Internal Transfer). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Automattic Woocommerce PaymentsAutomattic Woopayments | 12/4/2023 | 17/6/2026 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated. | |
| Modificada | Media (6.1) | 0.41% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Baja (3.7) | 0.46% | — | Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+3 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | |
| Modificada | Crítica (9.8) | 0.85% | — | Stripe Payment PRO | 1/3/2023 | 17/6/2026 | The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Alta (8.8) | 0.29% | — | Mercadopago Mercado Pago Payments FOR Woocommerce | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1. | |
| Modificada | Media (4.3) | 0.23% | — | Checkoutplugins Stripe Payments FOR Woocommerce | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 leads to settings change. | |
| Modificada | Media (5.4) | 0.54% | — | Tipsandtricks-hq Easy Accept Payments FOR Paypal | 13/2/2023 | 17/6/2026 | El complemento Easy Accept Payments for PayPal de WordPress anterior a 4.9.10 no valida ni escapa algunos de sus atributos de shortcode antes de devolverlos a una página/publicación donde está incrustado el shortcode, lo que podría permitir a los usuarios con el rol de colaborador y superior realizar ataques de… | |
| Modificada | Alta (7.2) | 0.95% | — | Thedotstore Conditional Payment Methods FOR Woocommerce | 16/1/2023 | 17/6/2026 | El complemento Conditional Payment Methods for WooCommerce de WordPress hasta la versión 1.0 no desinfecta ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que lleva a una inyección de SQL explotable por usuarios con privilegios elevados como administrador con un rol tan bajo como… | |
| Modificada | Media (5.3) | 0.63% | — | Paysafe Barzahlen Payment Module PHP SDK | 8/1/2023 | 17/6/2026 | Una vulnerabilidad clasificada como problemática ha sido encontrada en viafintech Barzahlen Payment Module PHP SDK hasta 2.0.0. La función de verificación del archivo src/Webhook.php es afectada por la vulnerabilidad. La manipulación conduce a una discrepancia temporal observable. La complejidad de un ataque es… | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | PHP Curl Class Project PHP Curl ClassHT Slider Range FOR Amazon Affiliates Project HT Slider Range FOR Amazon AffiliatesWoo-qiwi-payment-gatewayTeamleader CRM Forms+2 | 26/12/2022 | 17/6/2026 | php-mod/curl (un contenedor de la extensión PHP cURL) anterior a 2.3.2 permite XSS a través del parámetro clave post_file_path_upload.php y los datos POST en post_multidimensional.php. | |
| Modificada | Alta (7.2) | 0.71% | — | Paymattic Simple Payment Donations & Subscriptions | 5/9/2022 | 17/6/2026 | El plugin Simple Payment Donations & Subscriptions de WordPress versiones anteriores a 4.2.1, no sanea ni escapa de la entrada del usuario en sus formularios, lo que podría permitir a atacantes no autenticados llevar a cabo ataques de tipo Cross-Site Scripting contra administradores | |
| Modificada | Alta (7.2) | 0.96% | — | Student Registration AND FEE Payment System Project Student Registration AND FEE Payment System | 16/6/2022 | 17/6/2026 | Student Registration and Fee Payment System versión v1.0, es vulnerable a una Inyección SQL por medio del archivo /scms/student.php | |
| Modificada | Alta (8.8) | 0.81% | — | Videowhisper Micropayments | 20/4/2022 | 17/6/2026 | Una vulnerabilidad de tipo Cross-site request forgery (CSRF) en "MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership" versiones anteriores a 1.9.6, permite a un atacante remoto no autenticado secuestrar la autenticación de un administrador y llevar a cabo una operación no deseada por medio de… |