Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.45%—Tychesoftwares Order Delivery Date FOR WP E-commerce5/2/202417/6/2026
The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'available-days-tf' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
ModificadaAlta (7.2)0.53%—Webtoffee Order Export & Order Import FOR Woocommerce24/1/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.3.
ModificadaMedia (5.5)0.34%—Taurisoft ANY Sound Recorder22/1/202417/6/2026
A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerability affects unknown code of the component Registration Handler. The manipulation of the argument User Name/Key Code leads to memory corruption. It is possible to launch the attack on the local host.…
ModificadaMedia (5.4)0.53%—Codeastro Online Food Ordering System11/1/202417/6/2026
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file dishes.php. The manipulation of the argument res_id leads to cross site scripting. The attack may be launched remotely. The exploit has been…
ModificadaAlta (7.2)0.88%—Naziinfotech NI Purchase Order(po) FOR Woocommerce8/1/202417/6/2026
The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.
ModificadaCrítica (9.8)0.78%—Oretnom23 Online Food Ordering System5/1/202417/6/2026
A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.8)0.24%—Innovadeluxe Quick Order28/12/202317/6/2026
SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
ModificadaAlta (7.5)0.45%—Smackcoders Export ALL Posts, Products, Orders, Refunds & Users21/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
ModificadaAlta (8.8)0.25%—Quanticedge First Order Discount Woocommerce18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First Order Discount Woocommerce: from n/a through 1.21.
ModificadaAlta (8.8)0.49%—Fortinet FortiaiFortinet FortimailFortinet FortindrFortinet Fortirecorder+213/12/202317/6/2026
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x,…
ModificadaAlta (7.5)0.59%—Myprestamodules Orders (csv, Excel) Export PRO6/12/202317/6/2026
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from…
ModificadaCrítica (9.8)1.9%—Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller5/12/202317/6/2026
An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain…
ModificadaBaja (2.4)0.30%—Samsung Voice Recorder5/12/202317/6/2026
Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.
ModificadaMedia (6.1)0.40%—Q2w3 Post Order30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond, AndreSC Q2W3 Post Order allows Reflected XSS.This issue affects Q2W3 Post Order: from n/a through 1.2.8.
ModificadaAlta (7.5)0.53%—Smackcoders Export ALL Posts, Products, Orders, Refunds & Users30/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
ModificadaAlta (8.8)0.28%—Vjinfotech WOO Custom AND Sequential Order Number16/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in VJInfotech Woo Custom and Sequential Order Number plugin <= 2.6.0 versions.
AnalizadaAlta (8.8)0.67%—Myprestamodules Orders (csv, Excel) Export PRO15/11/202317/6/2026
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
ModificadaMedia (6.1)0.41%—Wpfactory Products, Order & Customers Export FOR Woocommerce14/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.
ModificadaMedia (4.8)0.40%—Walterpinem Oneclick Chat TO Order14/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2 versions.
ModificadaMedia (6.1)0.41%—Antonbond Additional Order Filters FOR Woocommerce13/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Anton Bond Additional Order Filters for WooCommerce plugin <= 1.10 versions.
ModificadaAlta (8.8)0.59%—Silbersaiten Order Duplicator7/11/202317/6/2026
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables…
ModificadaAlta (7.5)0.61%—Advanced Export Products Orders Cron CSV Excel Project Advanced Export Products Orders Cron CSV Excel7/11/202317/6/2026
Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
ModificadaMedia (5.4)0.31%—Brightplugins Pre-orders FOR Woocommerce6/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bright Plugins Pre-Orders for WooCommerce plugin <= 1.2.13 versions.
ModificadaAlta (7.2)0.68%—Cagewebdev Order Your Posts Manually3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Order Your Posts Manually allows SQL Injection.This issue affects Order Your Posts Manually: from n/a through 2.2.5.
ModificadaCrítica (9.8)0.70%—Projectworlds Online Food Ordering Script2/11/202317/6/2026
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.