Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.16% | — | Bitdefender Safepay | 12/4/2021 | 17/6/2026 | An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29. | |
| Modificada | Alta (8.8) | 3.7% | — | Bitdefender Safepay | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of… | |
| Modificada | Alta (8.8) | 3.8% | — | Bitdefender Safepay | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of… | |
| Modificada | Alta (8.8) | 3.7% | — | Bitdefender Safepay | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of… | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Patsatech Sagepay Server Gateway FOR Woocommerce | 9/1/2018 | 17/6/2026 | The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Tiomobilepay TIO Mobilepay - Bill Payments | 22/9/2014 | 17/6/2026 | The TIO MobilePay - Bill Payments (aka com.tionetworks.mobile.android.tioclient) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.1% | — | Woocommerce Sagepay Direct Payment Gateway Project Woocommerce Sagepay Direct Payment Gateway | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter. | |
| Modificada | Media (5.8) | 0.57% | — | OscommerceSagepay Sage PAY Direct Module | 4/11/2012 | 16/6/2026 | The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Baja (2.6) | 0.86% | — | Bluepay Manager | 19/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this vulnerability, saying that "it does not exist currently in the… | |
| Modificada | Media (6.4) | 1.1% | — | Alstrasoft Epay | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter. | |
| Modificada | Media (5.1) | 2.2% | — | Alstrasoft Epay | 28/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Enterprise 3.0 (formerly DoPays) allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters in (1) profile.htm, (2) card.htm, (3) bank.htm, (4) subscriptions.htm, (5) send.htm, (6) request.htm, (7) forgot.htm,… | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Alstrasoft Epay | 21/9/2005 | 16/6/2026 | Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Alstrasoft Epay | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) payment or (2) send parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Alstrasoft Epay | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the view parameter to reference a URL on a remote web server that contains the code. |