Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.1% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 13/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings. | |
| Modificada | Media (5.8) | 0.53% | — | Paypal WPS Toolkit | 6/11/2012 | 16/6/2026 | PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments PROZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP… | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Instant Payment NotificationZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than… | |
| Modificada | Media (5.8) | 0.57% | — | PaypalUbercart | 4/11/2012 | 16/6/2026 | The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | OscommercePaypal Payflow PRO Express Checkout | 4/11/2012 | 16/6/2026 | The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Brian Burton Paypal PRO Payflow ModuleOscommerce | 4/11/2012 | 16/6/2026 | The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | OscommercePaypal PRO | 4/11/2012 | 16/6/2026 | The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Akunamachata Paypal Express ModuleOscommerce | 4/11/2012 | 16/6/2026 | The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Invoicing | 4/11/2012 | 16/6/2026 | PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments Standard | 4/11/2012 | 16/6/2026 | PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation… | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments Standard | 4/11/2012 | 16/6/2026 | PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to… | |
| Modificada | Media (5.8) | 0.57% | — | Paypal IPN | 4/11/2012 | 16/6/2026 | The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | |
| Modificada | Media (5.8) | 0.91% | — | Paypal Merchant SDK | 4/11/2012 | 16/6/2026 | The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 5.7% | — | Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+1 | 4/11/2012 | 16/6/2026 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field… | |
| Modificada | Media (5) | 1.1% | — | Oscommerce Online MerchantPaypal Website Payments Standard Module | 19/9/2012 | 16/6/2026 | The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self. | |
| Modificada | Media (5) | 1.3% | — | Paypal Ubercart Payflow | 17/9/2012 | 16/6/2026 | The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors. | |
| Modificada | Baja (2.9) | 0.37% | — | Ebay Paypal | 9/11/2010 | 16/6/2026 | The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Paypalestores Paypal Estores | 26/3/2009 | 16/6/2026 | admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter. | |
| Modificada | Baja (3.5) | 0.84% | — | Drupal Asin Field ModuleDrupalDrupal E-commerce ModuleDrupal Fullname Field FOR CCK+6 | 22/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments… | |
| Modificada | Alta (7.5) | 1.2% | — | Easebay Resources Paypal Subscription Manager | 22/1/2007 | 16/6/2026 | SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Easebay Resources Paypal Subscription Manager | 22/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Duware DudownloadDuware DunewsDuware Dupaypal | 7/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Duware Dupaypal | 7/12/2006 | 16/6/2026 | SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: the iState parameter is already covered by CVE-2005-3976 and the iPro parameter is already covered by CVE-2005-2047. | |
| Modificada | Alta (7.5) | 1.7% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 7/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976. |