Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Onepay SRI Lanka Onepay Payment Gateway FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Onepay Sri Lanka onepay Payment Gateway For WooCommerce onepay-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects onepay Payment Gateway For WooCommerce: from n/a through <= 1.1.2. | |
| Aplazada | Media (6.5) | 0.44% | — | Cardpaysolutions Payment Gateway Authorize NET CIM FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in cardpaysolutions Payment Gateway Authorize.Net CIM for WooCommerce authnet-cim-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Authorize.Net CIM for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.5) | 0.39% | — | Peachpayments Wc-peach-payments-gatewayAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 3.3.6. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Application Gateway | 20/1/2026 | 17/6/2026 | IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Application Gateway | 20/1/2026 | 17/6/2026 | IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (5.3) | 0.26% | — | Float Payment GatewayAI | 14/1/2026 | 17/6/2026 | The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as failed. | |
| Aplazada | Media (5.3) | 0.26% | — | Aplazo Payment GatewayAI | 14/1/2026 | 17/6/2026 | The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to set any WooCommerce order to `pending… | |
| Aplazada | Media (5.3) | 0.26% | — | Payhere Payment Gateway Plugin FOR WoocommerceAI | 14/1/2026 | 17/6/2026 | The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of… | |
| Aplazada | Media (5.3) | 0.26% | — | Netcash Woocommerce Payment GatewayAI | 14/1/2026 | 17/6/2026 | The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_return_url function in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to mark any WooCommerce order as… | |
| Modificada | Alta (8.8) | 0.63% | — | Envoyproxy Gateway | 12/1/2026 | 15/7/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control… | |
| Aplazada | Alta (8.2) | 0.34% | — | Ipaymu Payment Gateway FOR WoocommerceAI | 7/1/2026 | 17/6/2026 | The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'check_ipaymu_response' function. This is due to the plugin not validating webhook request authenticity through signature verification or origin checks. This makes… | |
| Aplazada | Media (5.3) | 0.40% | — | Papaki Piraeus Bank Woocommerce Payment GatewayAI | 7/1/2026 | 17/6/2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and including, 3.1.4. This is due to missing authorization checks on the payment callback endpoint handler when processing the 'fail' callback from the payment gateway. This… | |
| Aplazada | Media (6.1) | 0.21% | — | Hblpay Payment GatewayAI | 7/1/2026 | 7/10/2026 | The HBLPAY Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cusdata’ parameter in all versions up to, and including, 5.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (6.7) | 0.12% | — | Dell Secure Connect Gateway | 6/1/2026 | 17/6/2026 | Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Media (4.3) | 0.15% | — | Quran GatewayAI | 20/12/2025 | 17/6/2026 | The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation in the quran_gateway_options function. This makes it possible for unauthenticated attackers to modify the plugin's display settings via a forged request… | |
| Aplazada | Media (5.3) | 0.27% | — | Yaadsarig Yaad Sarig Payment Gateway FOR WCAI | 16/12/2025 | 5/10/2026 | Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yaad Sarig Payment Gateway For WC: from n/a through <= 2.2.11. | |
| Aplazada | Media (5.3) | 0.37% | — | Campay Woocommerce Payment GatewayAI | 12/12/2025 | 7/10/2026 | The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly validating that a transaction has occurred through the payment gateway. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.22% | — | WOO Payment Gateway PayseraAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in paysera WooCommerce Payment Gateway - Paysera woo-payment-gateway-paysera allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Payment Gateway - Paysera: from n/a through <= 3.10.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Easy Payment WOO Paypal GatewayAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Easy Payment Payment Gateway for PayPal on WooCommerce woo-paypal-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway for PayPal on WooCommerce: from n/a through <= 9.0.53. | |
| Aplazada | Media (5.3) | 0.25% | — | Eupago Gateway FOR WoocommerceAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Eupago Eupago Gateway For Woocommerce eupago-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eupago Gateway For Woocommerce: from n/a through <= 4.7.1. | |
| Analizada | Alta (7.3) | 0.43% | — | Docker MCP Gateway | 3/12/2025 | 17/6/2026 | MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming transport mode, it is vulnerable to DNS rebinding. An attacker who can get a victim to visit a malicious website or be served a malicious advertisement can perform… | |
| Analizada | Media (6.5) | 0.41% | — | SplunkSplunk Cloud PlatformSplunk Secure Gateway | 3/12/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `label` column field… | |
| Analizada | Media (4.3) | 0.30% | — | SplunkSplunk Cloud PlatformSplunk Secure Gateway | 3/12/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that… | |
| Analizada | Media (6.9) | 0.37% | — | Portkey Gateway | 1/12/2025 | 17/6/2026 | Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously… | |
| Analizada | Media (4.3) | 0.29% | — | Opencode Ussd Gateway | 26/11/2025 | 17/6/2026 | Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs. |