Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.24%—Gavinr Inline FootnotesAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavinr Inline Footnotes inline-footnotes allows Stored XSS.This issue affects Inline Footnotes: from n/a through <= 2.3.0.
AplazadaMedia (4.3)0.28%—Print Invoice AND Delivery Notes FOR WoocommerceAI24/12/202417/6/2026
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaMedia (5.4)0.38%—Phpgurukul Online Notes Sharing Management System18/12/202417/6/2026
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.
AnalizadaMedia (4.3)0.34%—Phpgurukul Online Notes Sharing Management System18/12/202417/6/2026
An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.
ModificadaMedia (6.5)0.60%—Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce13/12/202417/6/2026
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2.
AplazadaMedia (6.1)0.21%—Wpclever WPC Order NotesAI11/12/202417/6/2026
The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the ajax_update_order_note() function. This makes it possible for unauthenticated attackers to inject malicious web…
AplazadaMedia (4.3)0.37%—Wpdash NotesAI23/11/202417/6/2026
The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments…
AnalizadaAlta (8.4)0.18%—Qnap Notes Station 322/11/202417/6/2026
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following…
AnalizadaCrítica (9.4)0.62%—Qnap Notes Station 322/11/202417/6/2026
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
AnalizadaAlta (8.7)1.6%—Qnap Notes Station 322/11/202417/6/2026
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
AnalizadaCrítica (9.3)0.93%—Qnap Notes Station 322/11/202417/6/2026
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
AnalizadaMedia (5.4)0.26%—Qnap Notes Station 36/9/202417/6/2026
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
AnalizadaMedia (5.4)0.26%—Qnap Notes Station 36/9/202417/6/2026
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
AnalizadaAlta (7.8)0.21%—Samsung Notes4/9/202417/6/2026
Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.
AnalizadaAlta (7.1)0.15%—Samsung Notes4/9/202417/6/2026
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
AnalizadaCrítica (9.8)0.63%—Samsung Notes4/9/202417/6/2026
Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.
AnalizadaAlta (7.8)0.24%—Samsung Notes4/9/202417/6/2026
Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.
AplazadaMedia (5.4)0.31%—Jamie Bergen Plugin Notes PlusAI19/8/202417/6/2026
Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7.
AplazadaMedia (6.5)0.26%—Jeroensormani WP Dashboard NotesAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11.
AnalizadaBaja (3.3)0.15%—Samsung Notes7/8/202417/6/2026
Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
AnalizadaBaja (3.3)0.15%—Samsung Notes7/8/202417/6/2026
Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
AnalizadaBaja (3.3)0.15%—Samsung Notes7/8/202417/6/2026
Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
AnalizadaBaja (3.3)0.15%—Samsung Notes7/8/202417/6/2026
Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
AnalizadaMedia (5.5)0.15%—Samsung Notes7/8/202417/6/2026
Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
AnalizadaMedia (5.5)0.15%—Samsung Notes7/8/202417/6/2026
Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.