Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.33%—Saeed Sattar Beglou Hesabfa Accounting Hesabfa AccountingAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saeed Sattar Beglou Hesabfa Accounting hesabfa-accounting allows Reflected XSS.This issue affects Hesabfa Accounting: from n/a through <= 2.1.2.
ModificadaCrítica (9.8)0.70%—Microsoft Account29/1/202517/6/2026
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (7.1)0.23%—Sabuj Kundu CBX Accounting & BookkeepingAI24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Accounting & Bookkeeping cbxwpsimpleaccounting allows Reflected XSS.This issue affects CBX Accounting & Bookkeeping: from n/a through <= 1.3.14.
AplazadaMedia (6.5)0.70%—Ldap-account-manager Ldap Account ManagerAI17/12/202417/6/2026
LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM does not properly sanitize configuration values, that are set via `mainmanage.php` and `confmain.php`. This allows setting arbitrary config values and thus…
AplazadaMedia (5.3)0.50%—Aslam Khan Gouran GOU Manage MY Account MenuAI13/12/202417/6/2026
Missing Authorization vulnerability in Aslam Khan Gouran Gou Manage My Account Menu gou-wc-account-tabs allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Gou Manage My Account Menu: from n/a through <= 1.0.1.8.
AplazadaMedia (6.1)0.35%—Accounting FOR WoocommerceAI5/12/202417/6/2026
The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (7.1)0.16%—Cmsaccount Photo Video StoreAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cmsaccount Photo Video Store photo-video-store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through <= 21.07.
ModificadaMedia (6.1)0.60%—Mediaticus Subaccounts FOR Woocommerce21/11/202417/6/2026
The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (4.2)0.42%—Teknigar Lock User AccountAI21/11/202417/6/2026
The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to permitting application password logins when user accounts are locked. This makes it possible for authenticated attackers, with existing application passwords, to interact with the…
AplazadaMedia (6.1)0.38%—Sysbasics Customize MY Account FOR WoocommerceAI9/11/202417/6/2026
The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 2.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (5.9)0.25%—KDE KmailAIKDE Kmail-account-wizardAI28/10/202417/6/2026
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to…
ModificadaAlta (7.5)0.56%—Opendaylight Authentication, Authorization AND Accounting15/9/202417/6/2026
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
AplazadaMedia (6.5)0.33%—SAP Production AND Revenue AccountingAI10/9/202417/6/2026
Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.
AnalizadaMedia (5.3)0.45%—Remyandrade Accounts Manager APP20/8/202417/6/2026
A vulnerability classified as problematic was found in SourceCodester Accounts Manager App 1.0. This vulnerability affects unknown code of the file update-account.php of the component Update Account Page. The manipulation of the argument Account Name/Username/Password/Link leads to cross site scripting. The attack can…
AnalizadaMedia (5.3)0.50%—Remyandrade Accounts Manager APP13/8/202417/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The manipulation of the argument account_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.66%—Remyandrade Accounts Manager APP13/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file /endpoint/delete-account.php. The manipulation of the argument account leads to sql injection. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.60%—Itsourcecode Laravel Accounting System6/8/202417/6/2026
A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit…
ModificadaAlta (8.8)0.36%—Themekraft Buddypress Woocommerce MY Account Integration. Create Woocommerce Member Pages10/6/202417/6/2026
Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.
ModificadaAlta (8.8)0.38%—Yithemes Woocommerce Account Funds9/6/202417/6/2026
Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.
AplazadaMedia (6.5)0.45%—Aptos Wisal Payroll AccountingAI24/5/202417/6/2026
Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable…
AplazadaBaja (3.5)0.33%—SAP Bank Account ManagementAI14/5/202417/6/2026
SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.
ModificadaAlta (8.8)0.51%—Themekraft Buddypress Woocommerce MY Account Integration18/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.
AplazadaAlta (7.2)0.73%—SAP Asset AccountingAI9/4/202417/6/2026
SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application.
AplazadaAlta (8.8)0.81%—Themekraft Buddypress Woocommerce MY Account IntegrationAI23/3/202417/6/2026
The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untrusted input in the get_simple_request function. This makes it possible for authenticated attackers,…
AnalizadaMedia (6.6)18%—Ldap-account-manager Ldap Account Manager18/3/202417/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to version 8.7, an attacker could exploit this by creating a PHP file and cause LAM to log some PHP code to this file. When the file is then…
Orbitaley — Vulnerabilidades