Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.41% | — | Snpdigital SaleskingAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15. | |
| Aplazada | Media (4.3) | 0.20% | — | Saleswonder Builder FOR Woocommerce Reviews Shortcodes ReviewshortAI | 19/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.3. | |
| Analizada | Alta (8.8) | 0.86% | — | Salesagility Suitecrm | 20/2/2024 | 17/6/2026 | Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. | |
| Modificada | Media (5) | 0.46% | — | Salesagility Suitecrm | 7/2/2024 | 17/6/2026 | Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF. | |
| Modificada | Alta (7.5) | 0.52% | — | Snpdigital Salesking | 24/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15. | |
| Modificada | Media (6.5) | 0.40% | — | Zorem Sales Report Email FOR Woocommerce | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8. | |
| Modificada | Crítica (9.8) | 0.57% | — | Saleswonder Webinarignition | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream &… | |
| Modificada | Alta (8.8) | 0.62% | — | Saleswonder Webinarignition | 29/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through… | |
| Modificada | Media (6.1) | 0.53% | — | Code-projects Point OF Sales AND Inventory Management System | 22/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (6.1) | 0.48% | — | Crmperks Integration FOR Salesforce AND Contact Form 7, Wpforms, Elementor, Ninja Forms | 19/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.3.3. | |
| Modificada | Media (5.3) | 3.0% | 💥 Exploit | Salesagility Suitecrm | 21/11/2023 | 17/6/2026 | SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the… | |
| Modificada | Media (4.8) | 0.39% | — | Wpdevart Countdown AND Countup, Woocommerce Sales Timer | 14/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Countdown and CountUp, WooCommerce Sales Timer plugin <= 1.8.2 versions. | |
| Modificada | Alta (8.8) | 1.0% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Alta (8.8) | 0.96% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Media (5.4) | 0.58% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Media (5.4) | 0.43% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Crítica (9.8) | 0.69% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Alta (8.8) | 0.81% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Media (4.3) | 0.50% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14. | |
| Modificada | Media (5.3) | 0.51% | — | Salesmanago | 21/10/2023 | 17/6/2026 | The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a SHA1 hash of the site URL and client ID found in the page source of the… | |
| Modificada | Media (6.1) | 0.44% | — | Saleswizard NSC | 20/10/2023 | 17/6/2026 | The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Modificada | Media (6.5) | 0.68% | — | Salesagility Suitecrm | 3/10/2023 | 17/6/2026 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. | |
| Modificada | Media (5.4) | 0.54% | — | Salesagility Suitecrm | 3/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. | |
| Modificada | Crítica (9.1) | 2.2% | — | Salesagility Suitecrm | 3/10/2023 | 17/6/2026 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1. | |
| Modificada | Media (5.3) | 0.42% | — | Oxid-esales Eshop | 2/8/2023 | 17/6/2026 | OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack. |