Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.33% | — | Elextensions Elex Woocommerce Dynamic Pricing AND DiscountsAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts allows Reflected XSS.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2. | |
| Modificada | Media (5.3) | 0.49% | — | Quanticedgesolutions Category Discount Woocommerce | 25/1/2024 | 17/6/2026 | The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in all versions up to, and including, 4.12. This makes it possible for unauthenticated attackers to modify product category discounts that… | |
| Modificada | Alta (8.8) | 0.25% | — | Quanticedge First Order Discount Woocommerce | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First Order Discount Woocommerce: from n/a through 1.21. | |
| Modificada | Media (5.3) | 0.58% | — | Rightpress Woocommerce Dynamic Pricing & Discounts | 20/10/2023 | 17/6/2026 | The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function which makes makes it possible for unauthenticated attackers to export the plugin's settings. | |
| Modificada | Alta (8.8) | 0.26% | — | Multidots Dynamic Pricing AND Discount Rules FOR Woocommerce | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin <= 2.4.0 versions. | |
| Modificada | Media (6.1) | 0.58% | — | Rightpress Woocommerce Dynamic Pricing AND Discounts | 7/6/2023 | 17/6/2026 | The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1. This is due to missing sanitization on the settings imported via the import() function. This makes it possible for unauthenticated attackers to import a settings file… | |
| Modificada | Media (6.1) | 0.79% | — | Flycart Discount Rules FOR Woocommerce | 17/7/2022 | 17/6/2026 | The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (5.5) | 1.8% | — | Discount Project DiscountDebian Linux | 15/6/2018 | 17/6/2026 | The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file. | |
| Modificada | Media (5.5) | 1.5% | — | Discount Project DiscountDebian Linux | 26/5/2018 | 17/6/2026 | The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html. | |
| Modificada | Media (5.5) | 1.6% | — | Discount Project DiscountDebian Linux | 26/5/2018 | 17/6/2026 | The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html. | |
| Modificada | Media (5.5) | 1.5% | — | Discount Project DiscountDebian Linux | 25/5/2018 | 17/6/2026 | The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html. | |
| Modificada | Crítica (9.8) | 2.1% | — | Ec-cube Discount Coupon | 1/8/2016 | 17/6/2026 | SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | Ubercart Discount Coupons Project Ubercart Discount Coupons | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Ubercart Discount Coupons module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms. | |
| Modificada | Media (5.4) | 0.27% | — | Onesolutionapps Aaaa Discount Bail | 21/10/2014 | 17/6/2026 | The AAAA Discount Bail (aka com.onesolutionapps.aaaadiscountbailandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mygoodhotels Booking Discount | 21/10/2014 | 17/6/2026 | The BOOKING DISCOUNT (aka com.wmygoodhotelscom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Discountedscripts E-gold Script Shop | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Discountedscripts ACG PTP | 5/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action. | |
| Modificada | Baja (3.5) | 0.84% | — | Discountedscripts ACG PTP | 26/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field under Credit/Debit Users, and the (3) FAQ question and (4) FAQ… | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Discountedscripts Quick Poll Script | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Michael Boehme Webdiscount E Shop Online Shop System | 15/9/2001 | 16/6/2026 | eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. |