Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Invoice GeneratorAI | 24/6/2026 | 25/6/2026 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. | |
| Aplazada | Crítica (10) | 0.86% | — | Easy InvoiceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Wpdesk Woocommerce PDF Invoices Packing SlipsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | |
| Aplazada | Crítica (10) | 0.56% | — | Rednao Woocommerce PDF Invoice BuilderAI | 15/6/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | Slicedinvoices Sliced InvoicesAI | 15/6/2026 | 17/6/2026 | WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious 'post'… | |
| Aplazada | Alta (8.1) | 0.27% | — | SolidinvoiceAI | 11/6/2026 | 17/6/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or… | |
| Aplazada | Alta (8.1) | 0.43% | — | SolidinvoiceAI | 11/6/2026 | 17/6/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every page of the… | |
| Pendiente de análisis | Crítica (9.2) | 32% | — | Poly VoiceAI | 1/6/2026 | 31/8/2026 | — | |
| Aplazada | Baja (2.1) | 0.34% | — | Sushmi-pal Invoice-systemAI | 25/5/2026 | 23/7/2026 | A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the component Profile Workflow. Such manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.34% | — | Sushmi-pal Invoice-systemAI | 25/5/2026 | 23/7/2026 | A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the component User Management Handler. This manipulation of the argument role causes improper authorization. It is possible to initiate the attack remotely. The exploit… | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Cosyvoice Project CosyvoiceAIPytorchAI | 12/5/2026 | 17/6/2026 | The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the --model_dir argument), the code uses torch.load() without the… | |
| Aplazada | Media (5.7) | 0.30% | — | CosyvoiceAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling the security-restrictive… | |
| Aplazada | Alta (7.3) | 0.37% | — | CosyvoiceAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the weights_only=True… | |
| Aplazada | Alta (7.3) | 0.36% | — | CosyvoiceAIPytorchAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the weights_only=True… | |
| Aplazada | Alta (7.3) | 0.36% | — | CosyvoiceAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embeddings, speaker embeddings, speech tokens) using torch.load() without enabling the… | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.48% | — | Code-projects Invoice SystemAILaravelAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.22% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Baja (2.1) | 0.35% | — | Code-projects Invoice SystemAILaravelAI | 27/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.35% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 0.35% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.35% | — | Code-projects Invoice SystemAILaravelAI | 27/4/2026 | 17/6/2026 | A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Analizada | Media (4.3) | 0.26% | — | Fortinet FortivoiceFortinet Fortindr | 14/4/2026 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only… |