Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.79% | — | Extra Checkout OptionsAI | 29/7/2026 | 30/7/2026 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged… | |
| Pendiente de análisis | Media (6.3) | 0.33% | — | GirocheckoutAI | 28/7/2026 | 30/7/2026 | Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. | |
| Aplazada | Media (6.5) | 0.22% | — | AcycheckerAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | |
| Aplazada | Media (5.9) | 0.24% | — | Checkout Field EditorAI | 27/7/2026 | 27/7/2026 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | |
| Aplazada | Media (6.5) | 0.79% | — | Themehigh Checkout Field Editor FOR WoocommerceAI | 25/7/2026 | 27/7/2026 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary… | |
| Aplazada | Media (6.4) | 0.42% | — | Equalize Digital Accessibility CheckerAI | 23/7/2026 | 23/7/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | Checkpoint Gaia PortalAI | 22/7/2026 | 24/7/2026 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. | |
| Pendiente de análisis | Crítica (9.1) | 1.0% | — | Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI | 22/7/2026 | 24/7/2026 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation… | |
| Analizada | Crítica (9.3) | 78% | ⚠ Explotación activa💥 Exploit | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/7/2026 | 10/8/2026 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security… | |
| Aplazada | Media (5.3) | 0.35% | — | CheckmkAI | 21/7/2026 | 22/7/2026 | Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules | |
| Aplazada | Media (5.2) | 0.18% | — | CheckmkAI | 14/7/2026 | 29/7/2026 | Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA instance. Without an explicit database configuration, the mk_sap_hana… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Openshift Incluster-checksAI | 13/7/2026 | 14/7/2026 | A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes. | |
| Aplazada | Media (5.3) | 0.42% | — | Easy Upload Files During CheckoutAI | 10/7/2026 | 10/7/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any nonce verification, capability check, or… | |
| Aplazada | Media (5.3) | 1.8% | — | Christopherthielen Check-peer-dependenciesAI | 8/7/2026 | 8/7/2026 | A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils.js of the component peerDependencies. This manipulation causes os command injection. The attack may be initiated remotely. The project was informed… | |
| Aplazada | Alta (7.5) | 0.35% | — | Checkview Automated TestingAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. | |
| Aplazada | Media (5.3) | 0.46% | — | 2download Connector FOR 2DL Hosted CheckoutAI | 19/6/2026 | 22/6/2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary… | |
| Aplazada | Media (4.3) | 0.40% | — | Equalize Digital Accessibility CheckerAI | 18/6/2026 | 18/6/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Analizada | Media (6.8) | 0.69% | — | Langchain Langgraph-checkpoint | 16/6/2026 | 24/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest… | |
| Aplazada | Alta (7.5) | 0.42% | — | ABC Crypto CheckoutAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. | |
| Aplazada | Alta (7.8) | 0.12% | — | Checkpoint Identity AgentAI | 11/6/2026 | 17/6/2026 | A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an… | |
| Analizada | Crítica (9.3) | 6.4% | ⚠ Explotación activa💥 Exploit | Checkpoint Gaia OSCheckpoint Gaia Embedded | 8/6/2026 | 4/8/2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | |
| Analizada | Media (4.8) | 0.24% | — | Checkmk | 8/6/2026 | 6/10/2026 | Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with… | |
| Analizada | Alta (8.5) | 0.24% | — | Checkmk | 8/6/2026 | 6/10/2026 | Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts… | |
| Analizada | Media (4.8) | 0.24% | — | Checkmk | 8/6/2026 | 6/10/2026 | Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes… | |
| Analizada | Media (6.3) | 0.31% | — | Checkmk | 8/6/2026 | 6/10/2026 | Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to… |