Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 3.4% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality implemented by AudioCodes_files/TestFax.php. When a fax "send" test is requested, the application builds a faxsender command line using… | |
| Analizada | Alta (8.5) | 0.20% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT… | |
| Analizada | Alta (8.5) | 0.20% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are requested through… | |
| Analizada | Alta (8.7) | 0.53% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via the download.php script. The endpoint exposes a file download mechanism that lacks access control, allowing remote, unauthenticated users to request files stored on the… | |
| Analizada | Media (6.9) | 0.46% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the… | |
| Analizada | Crítica (9.3) | 1.1% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates the directory if it… | |
| Analizada | Crítica (9.3) | 0.71% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files/utils/IVR/diagram/ajaxScript.php. The saveScript action writes attacker-supplied data directly to… | |
| Modificada | Alta (8.8) | 0.32% | — | Fortinet Fortivoice | 18/11/2025 | 17/6/2026 | An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS… | |
| Aplazada | Media (4.3) | 0.19% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.150. | |
| Aplazada | Media (4.3) | 0.19% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7. | |
| Aplazada | Alta (8.8) | 0.38% | — | Bplugins Voice FeedbackAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3. | |
| Modificada | Media (4.3) | 0.47% | — | Fortinet FortimailFortinet FortimanagerFortinet Fortimanager CloudFortinet Fortindr+8 | 14/10/2025 | 17/6/2026 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR… | |
| Analizada | Alta (7.2) | 1.3% | — | Fortinet Fortivoice | 14/10/2025 | 17/6/2026 | Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests. | |
| Analizada | Media (4.6) | 0.17% | — | Samsung Voice Recorder | 10/10/2025 | 17/6/2026 | Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen. | |
| Aplazada | Media (4.3) | 0.25% | — | Thedevoice Lazy BlocksAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in nK Lazy Blocks lazy-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lazy Blocks: from n/a through <= 4.1.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Wpdesk Flexible PDF Invoices FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-invoices allows Cross Site Request Forgery.This issue affects Flexible PDF Invoices for WooCommerce & WordPress: from n/a through <= 6.0.13. | |
| Aplazada | Alta (8.6) | 0.50% | — | Invoiceninja Invoice NinjaAI | 22/9/2025 | 17/6/2026 | Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files. | |
| Aplazada | Alta (7.5) | 0.63% | 💥 PoC | PropovoiceAI | 11/9/2025 | 17/6/2026 | The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the send_email() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Analizada | Baja (1.9) | 0.27% | — | Voice Changer Project Voice Changer | 29/8/2025 | 17/6/2026 | A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack on the local… | |
| Analizada | Media (5.4) | 0.27% | 💥 PoC | Solidinvoice | 29/8/2025 | 17/6/2026 | SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8. | |
| Analizada | Media (5.4) | 0.27% | 💥 PoC | Solidinvoice | 29/8/2025 | 17/6/2026 | SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8. | |
| Aplazada | Media (4.8) | 0.14% | — | Invoiceninja Invoice NinjaAI | 26/8/2025 | 17/6/2026 | Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a debugger, read or modify the process memory, inject code in the application's context despite being signed… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.… |