Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

477 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.41%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Payments. Successful attacks of this…
AnalizadaAlta (7.7)0.33%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in…
AnalizadaAlta (7.7)0.33%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in…
AnalizadaCrítica (9.8)0.51%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this…
AnalizadaAlta (7.1)0.30%—Oracle Payments18/8/202626/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this…
AplazadaMedia (6.5)0.42%—Piraeus Bank Woocommerce Payment GatewayAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
AplazadaAlta (7.5)0.42%—Duitku Payment GatewayAI18/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
AplazadaAlta (7.5)0.35%—Clink Bitcoin Lightning Payment GatewayAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
AplazadaMedia (5.3)0.16%—Fullworksplugins Quick Paypal PaymentsAI12/8/202626/8/2026
The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.
AplazadaMedia (5.3)0.32%—Payment Button FOR PaypalAI12/8/202626/8/2026
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
AplazadaMedia (5.3)0.16%—Paypal Payment Gateway FOR WoocommerceAI12/8/202626/8/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the…
AplazadaAlta (7.5)0.40%—Paymentplugins Payment Plugins FOR PaypalAI6/8/202626/8/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
AplazadaAlta (7.5)0.19%—Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI6/8/202626/8/2026
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own…
AplazadaMedia (5.3)0.31%—Mercadopago Mercado Pago Payments FOR WoocommerceAI6/8/202612/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
AplazadaAlta (7.5)0.35%—WP Full PAY Stripe Payment FormsAI6/8/202626/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to…
AplazadaMedia (5.3)0.40%—Woocommerce Paypal PaymentsAI1/8/202629/9/2026
El plugin WooCommerce PayPal Payments para WordPress es vulnerable a la revelación de información sensible debido a una Referencia Directa Insegura a Objeto en todas las versiones hasta la versión 3.3.2, inclusive, a través de la función 'enqueue_paypal_insights_script_on_order_received()' debido a la falta de…
AplazadaMedia (6.5)0.30%—Automattic Woocommerce PaymentsAI1/8/202626/8/2026
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
AplazadaMedia (5.3)0.30%—Direct Payments FOR WoocommerceAI1/8/202626/8/2026
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,…
AplazadaMedia (6.8)0.16%—NXP Mifare ClassicAICasfid Servicios Tecnologicos S.l.u Cashless Payment SystemAI28/7/202628/7/2026
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an…
AplazadaAlta (7.5)0.35%—Xendit PaymentAI27/7/202628/7/2026
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
AplazadaAlta (7.5)0.36%—Clover Payment Gateway BY ZaytechAI27/7/202627/7/2026
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by…
AplazadaMedia (5.3)0.61%—Paymentplugins Payment Plugins FOR StripeAI24/7/202624/7/2026
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary…
AplazadaAlta (7.5)0.35%—Payment Gateway FOR PaypalAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
AnalizadaAlta (8.1)0.36%—Oracle Payments21/7/202629/7/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this…
AnalizadaAlta (7.1)0.42%—Oracle Payments21/7/20263/8/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this…
Orbitaley — Vulnerabilidades