Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.4% | 💥 Exploit | Tychesoftwares Order Delivery Date PRO FOR Woocommerce | 26/4/2025 | 17/6/2026 | The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the… | |
| Aplazada | Alta (7.1) | 0.29% | — | Matat Technologies Deliver VIA Shipos FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matat Technologies Deliver via Shipos for WooCommerce wc-shipos-delivery allows Reflected XSS.This issue affects Deliver via Shipos for WooCommerce: from n/a through <= 2.1.7. | |
| Aplazada | Alta (8.8) | 0.22% | — | Foodbakery Delivery Restaurant DirectoryAI | 19/3/2025 | 17/6/2026 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save,… | |
| Aplazada | Media (5.9) | 0.54% | — | Powerpack Print Invoice Delivery NotesAI | 8/3/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Aplazada | Media (4.3) | 0.24% | — | Lafka Multi Store Burger Pizza Food DeliveryAI | 5/3/2025 | 17/6/2026 | The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.31% | — | Cisco Broadworks Application Delivery PlatformAI | 19/2/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Media (4.8) | 0.36% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips,… | |
| Analizada | Media (6.1) | 0.28% | — | Online Pizza Delivery System Project Online Pizza Delivery System | 23/1/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter. | |
| Aplazada | Media (6.1) | 0.36% | — | Deliver VIA ShiposAI | 9/1/2025 | 17/6/2026 | The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvsfw_bulk_label_url’ parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.28% | — | Print Invoice AND Delivery Notes FOR WoocommerceAI | 24/12/2024 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.5) | 0.47% | — | Webchunky Order Delivery Pickup Location Date TimeAI | 18/12/2024 | 17/6/2026 | Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery & Pickup Location Date Time: from n/a through <= 1.1.0. | |
| Modificada | Media (6.5) | 0.60% | — | Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2. | |
| Aplazada | Media (6.4) | 0.27% | — | Floristone Flower DeliveryAI | 4/12/2024 | 17/6/2026 | The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flower-delivery' shortcode in all versions up to, and including, 3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Halyra Collect AND Deliver Interface FOR WoocommerceAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3. | |
| Aplazada | Media (6.1) | 0.49% | — | Tychesoftwares Product Delivery Date FOR WoocommerceAI | 13/11/2024 | 17/6/2026 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.8) | 0.42% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 12/11/2024 | 17/6/2026 | Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA… | |
| Analizada | Alta (8.4) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 12/11/2024 | 17/6/2026 | Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway… | |
| Aplazada | Media (5.3) | 0.52% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Product Delivery Date for WooCommerce – Lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.2. | |
| Modificada | Crítica (9.8) | 0.53% | — | Buynowdepot Advanced Online Ordering AND Delivery Platform | 28/10/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wdesco Advanced Online Ordering and Delivery Platform advanced-online-ordering-and-delivery-platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery… | |
| Analizada | Media (6.1) | 0.39% | — | Tychesoftwares Product Delivery Date FOR Woocommerce | 4/10/2024 | 17/6/2026 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Media (6.9) | 0.71% | — | Rainniar Bike Delivery System | 6/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analizada | Alta (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Aplazada | Media (4.3) | 0.17% | — | Uploadcare File UploaderAIUploadcare Adaptive DeliveryAI | 1/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11. | |
| Analizada | Alta (7.2) | 0.64% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1. |