Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)6.7%💥 ExploitInvoiceninja Invoice NinjaAI7/1/202517/6/2026
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client.php file can be…
AplazadaCrítica (9.8)44%💥 ExploitCrater InvoiceAILaravelAI7/1/202517/6/2026
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies…
AplazadaAlta (7.5)0.61%—Service Shogun ACH Invoice APPAI7/1/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App ach-invoice-app allows PHP Local File Inclusion.This issue affects Ach Invoice App: from n/a through <= 1.0.1.
AplazadaMedia (4.3)0.28%—Print Invoice AND Delivery Notes FOR WoocommerceAI24/12/202417/6/2026
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaMedia (6.3)0.53%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known…
AnalizadaMedia (5.3)0.57%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.56%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AplazadaAlta (7.1)0.35%—Linknacional Invoice Payment FOR WoocommerceAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in linknacional Invoice Payment for WooCommerce invoice-payment-for-woocommerce allows Reflected XSS.This issue affects Invoice Payment for WooCommerce: from n/a through <= 1.7.2.
ModificadaMedia (6.5)0.60%—Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce13/12/202417/6/2026
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2.
AplazadaMedia (5.3)0.49%—Webventures Client Invoicing BY Sprout InvoicesAI9/12/202417/6/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0.
AplazadaMedia (6.1)0.43%—PDF Invoices AND Packing Slips Generator FOR WoocommerceAI23/11/202417/6/2026
The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaMedia (5.3)0.41%—Wpovernight Woocommerce PDF Invoices Packing SlipsAI29/10/202417/6/2026
Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 3.8.6.
AplazadaMedia (6.5)0.27%—Pepro DEV Group Pepro Ultimate InvoiceAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice pepro-ultimate-invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through <= 2.0.6.
AnalizadaMedia (5.3)0.41%—Oretnom23 Simple Invoice Generator System7/9/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql…
ModificadaMedia (4.8)0.40%—Expert Invoice Project Expert Invoice18/6/202417/6/2026
The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.32%—Slicedinvoices Sliced Invoices9/6/202417/6/2026
Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.
AnalizadaAlta (7.2)0.64%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels17/5/202417/6/2026
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.
AplazadaMedia (4.3)0.34%—Tychesoftwares Print Invoice AND Delivery Notes FOR WoocommerceAITychesoftwares Arconix ShortcodesAITychesoftwares Arconix FAQAI8/5/202417/6/2026
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ:…
ModificadaAlta (7.2)0.40%—Wpovernight Woocommerce PDF Invoices& Packing Slips2/5/202417/6/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be…
ModificadaMedia (6.1)0.57%—Wpovernight Woocommerce PDF Invoices& Packing Slips2/5/202417/6/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.38%—Peprodev Ultimate InvoiceAI17/4/202412/8/2026
Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0.
ModificadaMedia (5.3)0.44%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels6/4/202417/6/2026
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.55%—Acowebs PDF Invoices AND Packing Slips FOR Woocommerce28/3/202417/6/2026
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.
ModificadaMedia (6.1)0.40%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a…
ModificadaMedia (6.1)0.37%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels22/3/202417/6/2026
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for…