Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 6.7% | 💥 Exploit | Invoiceninja Invoice NinjaAI | 7/1/2025 | 17/6/2026 | Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client.php file can be… | |
| Aplazada | Crítica (9.8) | 44% | 💥 Exploit | Crater InvoiceAILaravelAI | 7/1/2025 | 17/6/2026 | A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies… | |
| Aplazada | Alta (7.5) | 0.61% | — | Service Shogun ACH Invoice APPAI | 7/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App ach-invoice-app allows PHP Local File Inclusion.This issue affects Ach Invoice App: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Print Invoice AND Delivery Notes FOR WoocommerceAI | 24/12/2024 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Media (6.3) | 0.53% | — | Invoiceplane | 16/12/2024 | 17/6/2026 | A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known… | |
| Analizada | Media (5.3) | 0.57% | — | Invoiceplane | 16/12/2024 | 17/6/2026 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.56% | — | Invoiceplane | 16/12/2024 | 17/6/2026 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.1) | 0.35% | — | Linknacional Invoice Payment FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in linknacional Invoice Payment for WooCommerce invoice-payment-for-woocommerce allows Reflected XSS.This issue affects Invoice Payment for WooCommerce: from n/a through <= 1.7.2. | |
| Modificada | Media (6.5) | 0.60% | — | Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2. | |
| Aplazada | Media (5.3) | 0.49% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0. | |
| Aplazada | Media (6.1) | 0.43% | — | PDF Invoices AND Packing Slips Generator FOR WoocommerceAI | 23/11/2024 | 17/6/2026 | The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.41% | — | Wpovernight Woocommerce PDF Invoices Packing SlipsAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 3.8.6. | |
| Aplazada | Media (6.5) | 0.27% | — | Pepro DEV Group Pepro Ultimate InvoiceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice pepro-ultimate-invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through <= 2.0.6. | |
| Analizada | Media (5.3) | 0.41% | — | Oretnom23 Simple Invoice Generator System | 7/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql… | |
| Modificada | Media (4.8) | 0.40% | — | Expert Invoice Project Expert Invoice | 18/6/2024 | 17/6/2026 | The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.32% | — | Slicedinvoices Sliced Invoices | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2. | |
| Analizada | Alta (7.2) | 0.64% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1. | |
| Aplazada | Media (4.3) | 0.34% | — | Tychesoftwares Print Invoice AND Delivery Notes FOR WoocommerceAITychesoftwares Arconix ShortcodesAITychesoftwares Arconix FAQAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ:… | |
| Modificada | Alta (7.2) | 0.40% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 2/5/2024 | 17/6/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be… | |
| Modificada | Media (6.1) | 0.57% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 2/5/2024 | 17/6/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.38% | — | Peprodev Ultimate InvoiceAI | 17/4/2024 | 12/8/2026 | Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0. | |
| Modificada | Media (5.3) | 0.44% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 6/4/2024 | 17/6/2026 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.55% | — | Acowebs PDF Invoices AND Packing Slips FOR Woocommerce | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7. | |
| Modificada | Media (6.1) | 0.40% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a… | |
| Modificada | Media (6.1) | 0.37% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 22/3/2024 | 17/6/2026 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for… |