Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

499 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.42%—Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
AplazadaCrítica (9.8)0.67%—Invoice GeneratorAI24/6/202625/6/2026
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a…
AplazadaAlta (7.5)0.42%—Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.
AplazadaCrítica (10)0.86%—Easy InvoiceAI15/6/202617/6/2026
Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
AplazadaAlta (7.2)0.54%—Wpdesk Woocommerce PDF Invoices Packing SlipsAI15/6/202617/6/2026
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
AplazadaCrítica (10)0.56%—Rednao Woocommerce PDF Invoice BuilderAI15/6/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
AplazadaAlta (7.1)0.23%—Slicedinvoices Sliced InvoicesAI15/6/202617/6/2026
WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious 'post'…
AplazadaAlta (8.1)0.27%—SolidinvoiceAI11/6/202617/6/2026
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or…
AplazadaAlta (8.1)0.43%—SolidinvoiceAI11/6/202617/6/2026
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every page of the…
Pendiente de análisisCrítica (9.2)32%—Poly VoiceAI1/6/202631/8/2026
—
AplazadaBaja (2.1)0.34%—Sushmi-pal Invoice-systemAI25/5/202623/7/2026
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the component Profile Workflow. Such manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely.…
AplazadaBaja (2.1)0.34%—Sushmi-pal Invoice-systemAI25/5/202623/7/2026
A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the component User Management Handler. This manipulation of the argument role causes improper authorization. It is possible to initiate the attack remotely. The exploit…
Pendiente de análisisAlta (8.8)0.68%—Cosyvoice Project CosyvoiceAIPytorchAI12/5/202617/6/2026
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the --model_dir argument), the code uses torch.load() without the…
AplazadaMedia (5.7)0.30%—CosyvoiceAI11/5/202617/6/2026
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling the security-restrictive…
AplazadaAlta (7.3)0.37%—CosyvoiceAI11/5/202617/6/2026
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the weights_only=True…
AplazadaAlta (7.3)0.36%—CosyvoiceAIPytorchAI11/5/202617/6/2026
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the weights_only=True…
AplazadaAlta (7.3)0.36%—CosyvoiceAI11/5/202617/6/2026
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embeddings, speaker embeddings, speech tokens) using torch.load() without enabling the…
AplazadaBaja (2)0.33%—Code-projects Invoice SystemAI27/4/202617/6/2026
A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.48%—Code-projects Invoice SystemAILaravelAI27/4/202617/6/2026
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.22%—Code-projects Invoice SystemAI27/4/202617/6/2026
A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
AplazadaBaja (2.1)0.35%—Code-projects Invoice SystemAILaravelAI27/4/202617/6/2026
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and…
AplazadaBaja (2.1)0.35%—Code-projects Invoice SystemAI27/4/202617/6/2026
A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out…
AplazadaBaja (2.1)0.35%—Code-projects Invoice SystemAI27/4/202617/6/2026
A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public…
AplazadaBaja (2.1)0.35%—Code-projects Invoice SystemAILaravelAI27/4/202617/6/2026
A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AnalizadaMedia (4.3)0.26%—Fortinet FortivoiceFortinet Fortindr14/4/202617/6/2026
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only…