Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Wpswings Wallet System FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Reflected XSS.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.8. | |
| Aplazada | Media (6.5) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows DOM-Based XSS.This issue affects Membership For WooCommerce: from n/a through <= 2.8.0. | |
| Analizada | Media (4.3) | 0.25% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to increase their own wallet balance,… | |
| Analizada | Media (4.3) | 0.15% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it… | |
| Modificada | Crítica (9.8) | 4.1% | 💥 Exploit | Wpswings Woocommerce Ultimate Gift Card | 28/2/2025 | 17/6/2026 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (5.4) | 0.31% | — | Wpswings Return Refund AND Exchange FOR Woocommerce | 14/2/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This… | |
| Analizada | Alta (7.5) | 0.47% | — | Wpswings Return Refund AND Exchange FOR Woocommerce | 14/2/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.78% | 💥 PoC | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 8/1/2025 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | |
| Aplazada | Media (6.5) | 0.29% | — | Ropeswinghld Speakout Email PetitionsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RopeSwingHld SpeakOut! Email Petitions speakout allows DOM-Based XSS.This issue affects SpeakOut! Email Petitions: from n/a through <= 4.4.2. | |
| Aplazada | Media (6.4) | 0.35% | — | Wpswings ONE Click Upsell Funnel FOR WoocommerceAI | 21/12/2024 | 17/6/2026 | The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wps_wocuf_pro_yes shortcode in… | |
| Aplazada | Alta (8.1) | 0.19% | — | Opendesign Drawings SDKAI | 4/12/2024 | 17/6/2026 | Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack… | |
| Aplazada | Alta (7.1) | 0.26% | — | Wpswings Woocommerce Ultimate Gift CardAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Reflected XSS.This issue affects WooCommerce Ultimate Gift Card: from n/a through < 2.9.1. | |
| Analizada | Crítica (9.8) | 1.3% | — | Webswing | 31/10/2024 | 17/6/2026 | Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server. | |
| Aplazada | Alta (8.8) | 1.1% | — | Woodwing Elvis DAMAIApache ANTAI | 23/9/2024 | 17/6/2026 | WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpswings Wallet System FOR WoocommerceAI | 13/8/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13. | |
| Analizada | Media (6.4) | 0.39% | — | Pterodactyl Wings | 3/5/2024 | 17/6/2026 | Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of the node hosting Wings in the pull endpoint. This would allow… | |
| Analizada | Alta (8.4) | 0.54% | — | Pterodactyl Wings | 3/5/2024 | 17/6/2026 | Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in… | |
| Aplazada | Media (5.4) | 0.21% | — | Wpswings Wallet System FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet System for WooCommerce: from n/a through 2.5.9. | |
| Aplazada | Media (5.4) | 0.39% | — | Wpswings Points AND Rewards FOR WoocommerceAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0. | |
| Aplazada | Alta (7.8) | 0.36% | — | Solidworks EdrawingsAI | 4/4/2024 | 17/6/2026 | Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT… | |
| Aplazada | Alta (7.8) | 0.32% | — | Solidworks EdrawingsAI | 4/4/2024 | 17/6/2026 | Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT… | |
| Modificada | Crítica (9.8) | 0.49% | — | Wpswings Points AND Rewards FOR Woocommerce | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0. | |
| Analizada | Alta (8.5) | 0.55% | — | Pterodactyl Wings | 13/3/2024 | 17/6/2026 | Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope of impact is exactly unknown, but reading files outside of a server's base… | |
| Modificada | Crítica (9.8) | 0.77% | — | Wpswings Coupon Referral Program | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4. | |
| Modificada | Alta (7.5) | 0.52% | — | Wpswings Coupon Referral Program | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2. |