Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Wpswings Wallet System FOR WoocommerceAI | 17/1/2026 | 17/6/2026 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'change_wallet_fund_request_status_callback' function in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Alta (7.5) | 0.24% | — | Pterodactyl PanelPterodactyl Wings | 6/1/2026 | 30/9/2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain… | |
| Aplazada | Media (6.3) | 0.20% | — | Wpswings Wallet System FOR WoocommerceAI | 5/1/2026 | 30/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through <= 2.7.3. | |
| Aplazada | Crítica (9.6) | 0.21% | — | GMO Wing Wing Wordpress MigratorAI | 30/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This issue affects WING WordPress Migrator: from n/a through <= 1.2.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpswings Membership FOR WoocommerceAI | 24/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Membership For WooCommerce: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7) | 0.15% | — | Opendesign Drawings SDKAI | 22/12/2025 | 17/6/2026 | A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 2026.12. Static object `COdaMfcAppApp theApp` may access `OdString::kEmpty` before its initialization. Due to undefined initialization order of static objects across translation units (Static… | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancorathemes WingerAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Winger winger allows PHP Local File Inclusion.This issue affects Winger: from n/a through <= 1.0.16. | |
| Aplazada | Alta (7.1) | 0.45% | — | Digitalpa Legality WhistleblowingAI | 9/12/2025 | 17/6/2026 | Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and… | |
| Aplazada | Media (5.4) | 0.17% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the wps_rma_fetch_order_msgs() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 21/11/2025 | 1/10/2026 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpswings Woocommerce Ultimate Points AND RewardsAI | 13/11/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Ultimate Points And Rewards: from n/a through <= 2.10.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Drawing-captcha APPAI | 16/10/2025 | 17/6/2026 | Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoints. It allows an attacker to manipulate the Host header in HTTP requests to generate malicious email confirmation links. These links can… | |
| Aplazada | Media (5.9) | 0.15% | — | Logo Software INC Tigerwings ERPAI | 3/10/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within an Executable. This issue affects TigerWings ERP: from 01.01.00 before 3.03.00. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpswings Upsell Order Bump Offer FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce upsell-order-bump-offer-for-woocommerce allows Stored XSS.This issue affects Upsell Order Bump Offer for WooCommerce: from n/a through <= 3.0.7. | |
| Aplazada | Alta (7.8) | 0.17% | — | 3DS Solidworks EdrawingsAI | 17/9/2025 | 25/9/2026 | A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.17% | — | 3DS Solidworks EdrawingsAI | 17/9/2025 | 25/9/2026 | A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file. | |
| Aplazada | Alta (7.8) | 0.17% | — | Solidworks EdrawingsAISolidworks DesktopAI | 17/9/2025 | 25/9/2026 | An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file. | |
| Aplazada | Media (5.3) | 0.24% | — | Wpswings PDF Generator FOR WPAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Generator for WordPress: from n/a through <= 1.5.4. | |
| Aplazada | Crítica (9.3) | 0.62% | — | Wpswings Woocommerce Ultimate Gift CardAI | 9/9/2025 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Blind SQL Injection.This issue affects WooCommerce Ultimate Gift Card: from n/a through <= 2.9.6. | |
| Aplazada | Alta (7.5) | 0.36% | — | Wpswings Membership FOR WoocommerceAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from n/a through <= 2.9.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Activity-log.com Profiler - What Slowing Down Your WPAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Profiler - What Slowing Down Your WP: from n/a through 1.0.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Wpswings Wallet System FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Cross Site Request Forgery.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.7. | |
| Aplazada | Alta (7.8) | 0.18% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted IPT file. | |
| Aplazada | Alta (7.8) | 0.18% | — | 3DS Solidworks EdrawingsAI | 15/7/2025 | 17/6/2026 | Use of Uninitialized Variable vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.19% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. |