Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.58% | — | Subscriptions FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaScript template… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contract.ejs renders… | |
| Aplazada | Media (6.1) | 0.32% | — | Swagger-typescript-api Swagger Typescript APIAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redirect, DNS rebinding,… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to… | |
| Aplazada | Alta (7.4) | 0.44% | — | Swagger-typescript-api Swagger Typescript APIAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref URLs, allowing an… | |
| Aplazada | Alta (7.5) | 0.51% | — | Salephpscripts WEB Directory FreeAI | 28/7/2026 | 28/7/2026 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.14% | — | HT Script Insert Headers AND Footers CodeAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Paid Member SubscriptionsAI | 27/7/2026 | 27/7/2026 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Header Footer Script AdderAI | 23/7/2026 | 23/7/2026 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Baja (1.9) | 1.1% | — | Syncfusion Ej2-javascript-ui-controlsAI | 22/7/2026 | 23/7/2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Scripting | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Scripting | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Scripting | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this… | |
| Analizada | Alta (7.8) | 2.5% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados') en Microsoft Exchange Server permite a un atacante no autorizado realizar suplantación (spoofing) a través de una red. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 14/7/2026 | 15/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 9/7/2026 | 9/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdeletequery.php. Such manipulation of the argument user_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument user_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.2) | 0.27% | — | Paid Member SubscriptionsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. |