Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Paypal OfficialAIPrestashopAI | 26/7/2024 | 17/6/2026 | In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment in case of disabled webhooks can be… | |
| Modificada | Alta (8.8) | 0.62% | — | Electronic Official Document Management System Project Electronic Official Document Management System | 15/7/2024 | 17/6/2026 | The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account. | |
| Aplazada | Media (5.3) | 0.55% | — | Friendlycaptcha OfficialAITypo3AITypo3 FormAI | 21/6/2024 | 17/6/2026 | An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the… | |
| Aplazada | Media (4.8) | 0.22% | — | Toyoko INN Official APP IOSAIToyoko INN Official APP AndroidAI | 13/3/2024 | 17/6/2026 | The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Crítica (9.8) | 1.3% | — | Plone Docker Official Image | 5/2/2024 | 9/7/2026 | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm). | |
| Modificada | Media (5.4) | 0.32% | — | Keap Official Opt-in Forms | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official Opt-in Forms allows Stored XSS.This issue affects Keap Official Opt-in Forms: from n/a through 1.0.11. | |
| Modificada | Media (6.1) | 0.92% | 💥 Exploit | Plone Docker Official Image | 25/1/2024 | 9/7/2026 | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers. | |
| Modificada | Media (4.8) | 0.40% | — | Keap Official Opt-in Forms | 15/1/2024 | 17/6/2026 | The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Crítica (9.8) | 0.55% | — | Jamieblomerus Unofficial Mobile Bankid Integration | 27/12/2023 | 17/6/2026 | Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an… | |
| Modificada | Media (4.8) | 0.52% | — | Official Integration FOR Billingo Project Official Integration FOR Billingo | 31/10/2022 | 17/6/2026 | The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 1.6% | — | Jiangqie Official Website Mini Program | 6/9/2021 | 17/6/2026 | The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues | |
| Modificada | Crítica (9.8) | 1.6% | — | Projectworlds Official CAR Rental System | 6/4/2020 | 17/6/2026 | Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt. | |
| Modificada | Alta (7.2) | 1.1% | — | Projectworlds Official CAR Rental System | 6/4/2020 | 17/6/2026 | An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files. | |
| Modificada | Media (4.3) | 0.41% | — | Dash CoreOfficialdapscoin Decentralized Anonymous Payment SystemPivx Private Instant Verified Transactions | 4/12/2019 | 17/6/2026 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact… | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Official Owasp ZAP | 4/4/2019 | 17/6/2026 | Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (5.4) | 0.27% | — | Pocketmags Wasps Official Programmes | 20/10/2014 | 17/6/2026 | The WASPS Official Programmes (aka com.triactivemedia.wasps) application @7F080130 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Automon Marcus Butler Unofficial | 20/10/2014 | 17/6/2026 | The Marcus Butler Unofficial (aka com.automon.ay.marcus.butler) application 1.4.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Automon Zoella Unofficial | 19/10/2014 | 17/6/2026 | The Zoella Unofficial (aka com.automon.ay.zoella) application 1.4.0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Automon Ledline.gr Official | 1/10/2014 | 17/6/2026 | The LedLine.gr Official (aka com.automon.ledline.gr) application 1.4.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.58% | — | Pizzahut Pizza HUT Japan Official Order Application | 10/6/2013 | 16/6/2026 | The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |