Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.34% | — | Mdalabar WOO Order Delivery Time LiteAI | 20/2/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2. | |
| Aplazada | Media (4.3) | 0.21% | — | Boxnow BOX NOW DeliveryAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in boxnow BOX NOW Delivery box-now-delivery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BOX NOW Delivery: from n/a through <= 3.0.2. | |
| Aplazada | Media (5.3) | 0.24% | — | MYD DeliveryAI | 31/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Eduardo Villão MyD Delivery myd-delivery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyD Delivery: from n/a through <= 1.7.1. | |
| Aplazada | Media (5.3) | 0.21% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in tychesoftwares Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.8) | 3.7% | 💥 Exploit | Woocommerce Delivery NotesAI | 24/12/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in… | |
| Aplazada | Media (5.3) | 0.27% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 23/12/2025 | 17/6/2026 | Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0. | |
| Modificada | Crítica (9.1) | 0.36% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Modificada | Alta (7.1) | 0.15% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Media (5.4) | 0.18% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not respond in… | |
| Aplazada | Media (5.4) | 0.23% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.3.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Matat Technologies Deliver VIA Shipos FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matat Technologies Deliver via Shipos for WooCommerce wc-shipos-delivery allows Cross Site Request Forgery.This issue affects Deliver via Shipos for WooCommerce: from n/a through <= 3.0.2. | |
| Aplazada | Media (4.3) | 0.24% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.1.0. | |
| Aplazada | Media (5.9) | 0.22% | — | Everythingwp Risk Free Cash ON Delivery COD WoocommerceAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in everythingwp Risk Free Cash On Delivery (COD) – WooCommerce risk-free-cash-on-delivery-cod-woocommerce allows Stored XSS.This issue affects Risk Free Cash On Delivery (COD) – WooCommerce: from n/a through <= 1.0.4. | |
| Analizada | Alta (8.8) | 8.2% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it | |
| Analizada | Crítica (9.2) | 20% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB… | |
| Analizada | Alta (8.8) | 0.83% | — | Ivanti Virtual Application Delivery Controller | 12/8/2025 | 17/6/2026 | Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password | |
| Analizada | Media (5.3) | 0.40% | — | Dell Digital Delivery | 4/8/2025 | 17/6/2026 | Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Media (4.3) | 0.28% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 11/7/2025 | 17/6/2026 | The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information | |
| Modificada | Media (4.8) | 0.26% | — | Cisco Broadworks Application Delivery Platform | 2/7/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Crítica (9.2) | 11% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 25/6/2025 | 17/6/2026 | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 4/8/2026 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Alta (8.7) | 6.2% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 17/6/2026 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway | |
| Aplazada | Alta (7.1) | 0.28% | — | Brewlabs WP Email DeliveryAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs WP Email Delivery wp-email-delivery allows Reflected XSS.This issue affects WP Email Delivery: from n/a through <= 1.20.11.23. | |
| Aplazada | Media (5.4) | 0.15% | — | Tychesoftwares Woocommerce Delivery NotesAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Cross Site Request Forgery.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.5.0. | |
| Analizada | Alta (7.1) | 0.26% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 20/5/2025 | 17/6/2026 | The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |