Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.43% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (7.1) | 0.21% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the… | |
| Aplazada | Alta (7.7) | 0.34% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.3) | 0.30% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 20/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.1) | 0.13% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search /… | |
| Aplazada | Alta (7.1) | 0.40% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (7.1) | 0.40% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (8.2) | 0.30% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.5) | 0.39% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (8.2) | 0.34% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Media (6.9) | 0.51% | — | Craft CommerceAI | 14/9/2026 | 30/9/2026 | Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthenticated attacker can submit couponCode values to actionUpdateCart for the… | |
| Aplazada | Baja (2.1) | 0.39% | — | Jaygajera17 E-commerce-project-springbootAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to… | |
| Aplazada | Media (5.3) | 0.29% | — | Deposits AND Partial Payments FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Ideasoft Smart E-commerceAI | 11/9/2026 | 25/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0. | |
| Aplazada | Media (5.3) | 0.30% | — | Moreconvert Woocommerce WishlistAI | 11/9/2026 | 11/9/2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mipl Grouped Checkout Fields FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.1) | 0.37% | — | Themify Woocommerce Product FilterAI | 11/9/2026 | 11/9/2026 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.32% | — | OTP Login Register WoocommerceAI | 11/9/2026 | 11/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled… | |
| Aplazada | Alta (7.5) | 0.35% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | |
| Aplazada | Alta (8.6) | 0.53% | — | Studiowombat Advanced Product Fields Extended FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | |
| Aplazada | Alta (7.5) | 0.39% | — | Thank YOU Page Customizer FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Robokassa Payment Gateway FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |
| Aplazada | Alta (7.2) | 0.46% | — | Registration Form FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can… | |
| Aplazada | Crítica (9.1) | 0.45% | — | Zipmoney Payments FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to… | |
| Aplazada | Alta (7.5) | 0.26% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption… |