Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.51%—Standalonetech Terawallet12/7/202417/6/2026
The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (4.8)0.34%—Standalonetech Terawallet18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech TeraWallet – For WooCommerce allows Stored XSS.This issue affects TeraWallet – For WooCommerce: from n/a through 1.5.0.
AplazadaMedia (5.4)0.21%—Wpswings Wallet System FOR WoocommerceAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet System for WooCommerce: from n/a through 2.5.9.
ModificadaMedia (4.3)0.44%—Standalonetech Terawallet13/3/202417/6/2026
The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the terawallet_export_user_search() function in all versions up to, and including, 1.4.10. This makes it possible…
ModificadaCrítica (9.8)1.8%💥 PoCMiniorange Web3 - Crypto Wallet Login & NFT Token Gating12/2/202417/6/2026
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an…
ModificadaAlta (7.5)0.55%—Binance Trust Wallet8/2/202417/6/2026
The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can…
ModificadaAlta (7.5)0.49%—Multisigwallet Project Multisigwallet19/1/202417/6/2026
MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.
ModificadaCrítica (9.8)1.00%—Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+1119/1/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long…
ModificadaAlta (7.5)0.73%—Skale Sgxwallet25/8/202317/6/2026
An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGenerateEcdsaKey component.
ModificadaAlta (7.5)0.98%—Skale Sgxwallet25/8/202317/6/2026
Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the trustedBlsSignMessage function.
ModificadaCrítica (9.8)1.1%—Vivawallet Viva Wallet11/7/202317/6/2026
SQL injection vulnerability found in PrestaShop vivawallet v.1.7.10 and before allows a remote attacker to gain privileges via the vivawallet() module.
ModificadaCrítica (9.8)1.1%—Miniorange Web3 - Crypto Wallet Login & NFT Token Gating30/6/202317/6/2026
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user…
ModificadaMedia (5.9)1.0%💥 PoCTrustwallet Trust Wallet Browser ExtensionTrustwallet Trust Wallet Core27/4/202317/6/2026
Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only…
ModificadaMedia (5.7)0.38%—Uniswap Web3-react Coinbase-walletUniswap Web3-react Eip1193Uniswap Web3-react MetamaskUniswap Web3-react Walletconnect17/4/202317/6/2026
@web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId`…
ModificadaMedia (5.5)0.30%—Samourai-wallet-android Project Samourai-wallet-android4/3/202317/6/2026
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be insufficient in this situation.
ModificadaMedia (4.3)0.22%—Standalonetech Terawallet1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.
ModificadaAlta (8.8)0.26%—Standalonetech Terawallet2/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions.
ModificadaCrítica (9.8)0.63%—Piwallet Project Piwallet11/1/202317/6/2026
A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patch is identified as b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. It is recommended to apply a patch to…
ModificadaMedia (4.3)0.60%—Standalonetech Terawallet29/11/202217/6/2026
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaMedia (6.1)0.79%—Greenwallet Woocommerce Green Wallet Gateway8/6/202217/6/2026
The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter before outputting it to the page, leading to a Reflected Cross-Site Scripting vulnerability.
ModificadaMedia (5.5)0.21%—Samsung Blockchain Wallet8/12/202117/6/2026
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
ModificadaCrítica (9.8)1.7%—Skale Sgxwallet27/9/202117/6/2026
An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a valid address. This address is then freed, resulting in…
ModificadaAlta (7.5)2.3%—Skale Sgxwallet27/9/202117/6/2026
An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible in latest sgxwallet v1.77.0
ModificadaCrítica (9.8)1.1%—Tronlink Wallet22/7/201917/6/2026
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.
ModificadaMedia (6.5)1.3%—Tronlink Wallet22/7/201917/6/2026
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log…
Orbitaley — Vulnerabilidades