Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.62% | — | Villatheme Orders Tracking FOR WoocommerceAI | 14/5/2024 | 17/6/2026 | The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Aplazada | Media (4.3) | 0.25% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.3) | 0.58% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Fmemodules PreorderandnoticationAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Helloshop DeliveryorderautoupdateAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function. | |
| Aplazada | Crítica (10) | 1.1% | — | Nmedia OrderconvoAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4. | |
| Aplazada | Crítica (9.1) | 0.69% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 25/4/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This issue affects Advanced Order Export For WooCommerce: from n/a through 3.4.4. | |
| Aplazada | Media (6.5) | 0.44% | — | Xfinity Order Limit FOR WoocommerceAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Xfinity Soft Order Limit for WooCommerce.This issue affects Order Limit for WooCommerce: from n/a through 2.0.0. | |
| Aplazada | Media (6.5) | 0.32% | — | Gloriafood Restaurant Menu Food Ordering System Table ReservationAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation allows Stored XSS.This issue affects Restaurant Menu – Food Ordering System – Table Reservation: from n/a through 2.4.1. | |
| Aplazada | Media (4.3) | 0.46% | — | Nuggethon Custom Order Statuses FOR WoocommerceAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2. | |
| Aplazada | Media (4.3) | 0.21% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce.This issue affects Order Delivery Date for WooCommerce: from n/a through 3.20.2. | |
| Modificada | Alta (8.8) | 0.22% | — | Zaytech Smart Online Order FOR Clover | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. | |
| Aplazada | Media (6.5) | 0.36% | — | Walterpinem Oneclick Chat TO OrderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem OneClick Chat to Order allows Stored XSS.This issue affects OneClick Chat to Order: from n/a through 1.0.5. | |
| Analizada | Alta (7.5) | 0.83% | — | Myprestamodules Orders (csv, Excel) Export PRO | 20/3/2024 | 17/6/2026 | An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. | |
| Aplazada | Media (5.3) | 0.52% | — | Order TIP FOR WoocommerceAI | 20/3/2024 | 17/6/2026 | The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_tips_to_csv() function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to export the plugin's order fees. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Open Source Medicine Medicine Ordering SystemAI | 19/3/2024 | 17/6/2026 | Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php. | |
| Aplazada | Alta (7.1) | 0.38% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Modificada | Media (5.4) | 0.34% | — | Zaytech Smart Online Order FOR Clover | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zaytech Smart Online Order for Clover allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. | |
| Analizada | Crítica (9.8) | 0.56% | — | Fmemodules B2B Quick Order Form | 14/3/2024 | 17/6/2026 | SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods. | |
| Modificada | Media (4.3) | 0.24% | — | Cozyvision SMS Alert Order Notifications | 13/3/2024 | 17/6/2026 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and… | |
| Analizada | Crítica (9.8) | 0.59% | — | Cleanpresta CD Custom Fields 4 Orders | 8/3/2024 | 17/6/2026 | In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Analizada | Baja (2.4) | 0.23% | — | Samsung Voice Recorder | 5/3/2024 | 17/6/2026 | Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen. | |
| Analizada | Media (4.6) | 0.25% | — | Samsung Voice Recorder | 5/3/2024 | 17/6/2026 | Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen. | |
| Modificada | Alta (8.8) | 0.28% | — | Nuggethon Custom Order Status Manager FOR Woocommerce | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2. | |
| Modificada | Crítica (9.8) | 0.69% | — | Oretnom23 Online Medicine Ordering System | 14/2/2024 | 17/6/2026 | Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product. |