Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | Oracle Payments | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.42% | — | Oracle Payments | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Aplazada | Media (6.5) | 0.33% | — | Peachpayments Wc-peach-payments-gatewayAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2. | |
| Analizada | Media (4.8) | 0.22% | — | Stella Commerce Realex / Global Payments | 10/7/2026 | 6/8/2026 | Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2. | |
| Aplazada | Alta (7.5) | 0.35% | — | Nowpayments FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Stripe PaymentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions. | |
| Aplazada | Media (5.9) | 0.34% | — | Best PaymentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions. | |
| Aplazada | Media (5.1) | 0.19% | — | Stripe PaymentsAI | 8/6/2026 | 27/8/2026 | WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the… | |
| Aplazada | Alta (8.2) | 0.46% | — | Woocommerce Paypal PaymentsAI | 23/5/2026 | 23/7/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an… | |
| Aplazada | Media (5.3) | 0.41% | — | Mercadopago Mercado Pago Payments FOR WoocommerceAI | 6/5/2026 | 25/7/2026 | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code… | |
| Aplazada | Media (5.3) | 0.32% | — | Zealousweb Accept Paypal Payments Using Contact Form 7AI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through <= 4.0.4. | |
| Aplazada | Media (5.4) | 0.22% | — | Globalpayments Global Payments WoocommerceAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Server Side Request Forgery.This issue affects GlobalPayments WooCommerce: from n/a through <= 1.18.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Woocommerce WoopaymentsAI | 31/3/2026 | 17/6/2026 | The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin… | |
| Aplazada | Alta (8.8) | 0.37% | — | Maximsecudeal Secudeal Payments FOR EcommerceAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in maximsecudeal Secudeal Payments for Ecommerce secudeal-payments-for-ecommerce allows Object Injection.This issue affects Secudeal Payments for Ecommerce: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mollie Payments FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce allows Reflected XSS.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.1.1. | |
| Aplazada | Media (6.5) | 0.39% | — | Peachpayments Wc-peach-payments-gatewayAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 3.3.6. | |
| Aplazada | Alta (7.5) | 1.8% | 💥 Exploit | Yoco PaymentsAI | 7/1/2026 | 17/6/2026 | The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via the file parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Aplazada | Media (4.3) | 0.30% | — | Digages Direct Payments WPAI | 31/12/2025 | 28/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Digages Direct Payments WP direct-payments-wp allows Retrieve Embedded Sensitive Data.This issue affects Direct Payments WP: from n/a through <= 1.3.2. | |
| Aplazada | Media (4.3) | 0.26% | — | Digages Direct-payments-wpAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in Digages Direct Payments WP direct-payments-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Direct Payments WP: from n/a through <= 1.3.2. | |
| Aplazada | Media (6.1) | 0.25% | — | Zealousweb Accept Stripe Payments Using Contact Form 7AI | 12/12/2025 | 30/9/2026 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.32% | — | Automattic Woocommerce PaymentsAI | 10/9/2025 | 17/6/2026 | The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 1.117.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Paypal PaymentsAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Site Request Forgery.This issue affects Quick Paypal Payments: from n/a through <= 5.7.46. | |
| Aplazada | Media (4.3) | 0.14% | — | Trust Payments Gateway FOR WoocommerceAI | 4/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Library) trust-payments-gateway-3ds2 allows Cross Site Request Forgery.This issue affects Trust Payments Gateway for WooCommerce (JavaScript Library): from n/a through <= 1.3.6. | |
| Aplazada | Media (6.5) | 0.29% | — | Mollie Payments FOR WoocommerceAI | 2/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.0.2. | |
| Analizada | Media (4.3) | 0.17% | — | Videowhisper Micropayments | 28/6/2025 | 17/6/2026 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the adminOptions() function. This makes it possible for… |