Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
477 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.41% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.7) | 0.33% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in… | |
| Analizada | Alta (7.7) | 0.33% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Aplazada | Media (6.5) | 0.42% | — | Piraeus Bank Woocommerce Payment GatewayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Duitku Payment GatewayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Clink Bitcoin Lightning Payment GatewayAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Fullworksplugins Quick Paypal PaymentsAI | 12/8/2026 | 26/8/2026 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid. | |
| Aplazada | Media (5.3) | 0.32% | — | Payment Button FOR PaypalAI | 12/8/2026 | 26/8/2026 | The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount. | |
| Aplazada | Media (5.3) | 0.16% | — | Paypal Payment Gateway FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the… | |
| Aplazada | Alta (7.5) | 0.40% | — | Paymentplugins Payment Plugins FOR PaypalAI | 6/8/2026 | 26/8/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments | |
| Aplazada | Alta (7.5) | 0.19% | — | Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI | 6/8/2026 | 26/8/2026 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own… | |
| Aplazada | Media (5.3) | 0.31% | — | Mercadopago Mercado Pago Payments FOR WoocommerceAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | WP Full PAY Stripe Payment FormsAI | 6/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to… | |
| Aplazada | Media (5.3) | 0.40% | — | Woocommerce Paypal PaymentsAI | 1/8/2026 | 29/9/2026 | El plugin WooCommerce PayPal Payments para WordPress es vulnerable a la revelación de información sensible debido a una Referencia Directa Insegura a Objeto en todas las versiones hasta la versión 3.3.2, inclusive, a través de la función 'enqueue_paypal_insights_script_on_order_received()' debido a la falta de… | |
| Aplazada | Media (6.5) | 0.30% | — | Automattic Woocommerce PaymentsAI | 1/8/2026 | 26/8/2026 | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders. | |
| Aplazada | Media (5.3) | 0.30% | — | Direct Payments FOR WoocommerceAI | 1/8/2026 | 26/8/2026 | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,… | |
| Aplazada | Media (6.8) | 0.16% | — | NXP Mifare ClassicAICasfid Servicios Tecnologicos S.l.u Cashless Payment SystemAI | 28/7/2026 | 28/7/2026 | Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an… | |
| Aplazada | Alta (7.5) | 0.35% | — | Xendit PaymentAI | 27/7/2026 | 28/7/2026 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | |
| Aplazada | Alta (7.5) | 0.36% | — | Clover Payment Gateway BY ZaytechAI | 27/7/2026 | 27/7/2026 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by… | |
| Aplazada | Media (5.3) | 0.61% | — | Paymentplugins Payment Plugins FOR StripeAI | 24/7/2026 | 24/7/2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary… | |
| Aplazada | Alta (7.5) | 0.35% | — | Payment Gateway FOR PaypalAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Payments | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.42% | — | Oracle Payments | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… |