Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

477 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Idokd Simple PaymentAI11/9/202611/9/2026
Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
AplazadaMedia (5.3)0.29%—Deposits AND Partial Payments FOR WoocommerceAI11/9/202611/9/2026
Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.
AplazadaMedia (5.9)0.16%—Payment Gateway PaypayAI11/9/202611/9/2026
The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.
AplazadaMedia (6.5)0.33%—Robokassa Payment Gateway FOR WoocommerceAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
AplazadaCrítica (9.1)0.45%—Zipmoney Payments FOR WoocommerceAI10/9/202610/9/2026
The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to…
AplazadaMedia (5.9)0.23%—Paymentplugins Payment Plugins FOR Paypal WoocommerceAI9/9/20269/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires…
AplazadaMedia (5.3)0.34%—Payment Plugins FOR Paypal WoocommerceAI9/9/20269/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and…
AplazadaMedia (5.3)0.34%—Paymentpluginsforstripe Payment Plugins FOR StripeAI9/9/20269/9/2026
The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by…
AplazadaMedia (5.3)0.30%—Accept Stripe PaymentsAI5/9/20268/9/2026
The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who…
AplazadaMedia (4.3)0.30%—Accept Stripe PaymentsAI5/9/20268/9/2026
The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.
AplazadaMedia (5.3)0.16%—Epayco Payment GatewayAI4/9/20268/9/2026
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
AplazadaAlta (7.1)0.25%—Idokd Simple PaymentAI3/9/20263/9/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
AplazadaMedia (4.3)0.25%—WP Full PAY Stripe Payment FormsAI29/8/202631/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation…
AplazadaCrítica (9.1)0.24%—Totalpaymentprocessing Total Processing Card PaymentsAI29/8/202631/8/2026
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host…
AplazadaAlta (7.5)0.35%—Idokd Simple PaymentAI28/8/202628/8/2026
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
AplazadaMedia (4.3)0.25%—WP Full PAY Stripe Payment FormsAI26/8/202626/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other…
AplazadaMedia (5.3)0.34%—WP Full PAY Stripe Payment FormsAI26/8/202626/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.
AplazadaAlta (7.1)0.25%—Stripe PaymentsAI24/8/202626/8/2026
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
AplazadaMedia (5.3)0.33%—Conekta Payment GatewayAI22/8/202626/8/2026
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
AnalizadaMedia (6.3)0.32%—Zenhive Machine Payments Protocol19/8/202610/9/2026
Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence:…
AnalizadaAlta (8.3)0.59%—Zenhive Machine Payments Protocol19/8/202610/9/2026
Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas,…
AnalizadaAlta (8.2)0.60%—Zenhive Machine Payments Protocol19/8/202610/9/2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under verification through an attribution nonce…
AnalizadaAlta (8.7)0.60%—Zenhive Machine Payments Protocol19/8/202610/9/2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native).…
AnalizadaAlta (8.2)0.35%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this…
AnalizadaAlta (7.4)0.34%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this…
Orbitaley — Vulnerabilidades