Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in '/login.php' parameter. | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in '/candidate/controller.php' parameter. | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/AttendanceMonitoring/department/index.php'… | |
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in… | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in 'Attendance' and 'YearLevel' in… | |
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in '/admin/mod_reports/index.php' parameter. | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in… | |
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_users/index.php' parameter. | |
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_room/index.php' parameter. | |
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/index.php' parameter. | |
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/controller.php'… | |
| Analizada | Crítica (9.8) | 0.46% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in '/admin/mod_reports/printreport.php' parameter. | |
| Analizada | Media (6.1) | 0.28% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/index.php'. | |
| Analizada | Media (6.1) | 0.28% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/printreport.php'. | |
| Analizada | Media (6.1) | 0.28% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and 'accomodation' parameters in '/index.php'. | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in '/admin/mod_reports/printreport.php' parameter. | |
| Analizada | Media (6.8) | 0.45% | — | Bharatkambariya Donation Block FOR Paypal | 30/7/2024 | 17/6/2026 | The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability | |
| Aplazada | Alta (7.5) | 0.39% | — | Paypal OfficialAIPrestashopAI | 26/7/2024 | 17/6/2026 | In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment in case of disabled webhooks can be… | |
| Modificada | Media (5.4) | 0.32% | — | Mohsinrasool Paypal PAY Now, BUY Now, Donation AND Cart Buttons Shortcode | 21/6/2024 | 17/6/2026 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | |
| Modificada | Media (4.8) | 0.32% | — | Mohsinrasool Paypal PAY Now, BUY Now, Donation AND Cart Buttons Shortcode | 21/6/2024 | 17/6/2026 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Analizada | Media (5.4) | 0.25% | — | Wp-ecommerce Recurring Paypal Donations | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through 1.7. | |
| Analizada | Alta (8.8) | 0.38% | — | Codepeople CP Contact Form With Paypal | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34. | |
| Aplazada | Media (4.4) | 0.27% | — | Paypal PAY NOW BUY NOW Donation AND Cart Buttons ShortcodeAI | 23/5/2024 | 17/6/2026 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 0.40% | — | Wpplugin Paypal & Stripe Add-on | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0. | |
| Modificada | Alta (8.8) | 0.22% | — | Wpplugin Easy Paypal & Stripe BUY NOW Button | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1. |