Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Androidbubble WP Sort OrderAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Food Order SystemAI | 15/8/2026 | 20/8/2026 | A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online Food Order SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Aplazada | Alta (7.1) | 0.25% | — | Zaytech Smart Online Order FOR CloverAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | |
| Aplazada | Media (5.3) | 0.34% | — | Order Sync With Zendesk FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer… | |
| Aplazada | Media (6.5) | 0.30% | — | Piweb Cancel Order Refund RequestAI | 9/8/2026 | 26/8/2026 | The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a… | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpclever WPC Order TIPAI | 9/8/2026 | 26/8/2026 | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and… | |
| Aplazada | Alta (7.2) | 0.46% | — | Order Delivery DateAI | 6/8/2026 | 12/8/2026 | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Chat ON Desk Order NotificationsAI | 1/8/2026 | 26/8/2026 | The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS… | |
| Aplazada | Media (4.4) | 0.52% | — | SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI | 28/7/2026 | 28/7/2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Order Management | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Order Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Order Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Peoplesoft Enterprise SCM Order Management | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Order Management.… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Peoplesoft Enterprise SCM Order Management | 21/7/2026 | 4/8/2026 | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management.… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Peoplesoft Enterprise SCM Order Management | 21/7/2026 | 4/8/2026 | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Order Management executes… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Order Management | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful… | |
| Analizada | Media (6.4) | 0.23% | — | Oracle Order Management | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the… | |
| Analizada | Media (6.8) | 0.40% | — | Oracle Order Management | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. While the… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdesk Flexible Refund AND Return Order FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <=… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Food Order SystemAI | 9/7/2026 | 9/7/2026 | A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.3) | 0.47% | — | Bulk Order Update FOR WoocommerceAI | 8/7/2026 | 8/7/2026 | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST… | |
| Analizada | Alta (8.8) | 0.36% | — | UI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition FirmwareUI Unifi Dream Machine PRO MAX FirmwareUI Unifi Dream Machine Beast Firmware+15 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device. |