Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | PHP Curl Class Project PHP Curl ClassHT Slider Range FOR Amazon Affiliates Project HT Slider Range FOR Amazon AffiliatesWoo-qiwi-payment-gatewayTeamleader CRM Forms+2 | 26/12/2022 | 17/6/2026 | php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. | |
| Modificada | Media (6.1) | 0.67% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 29/8/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 0.81% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 11/7/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks. | |
| Modificada | Media (4.8) | 1.2% | 💥 Exploit | Wpovernight Woocommerce PDF Invoices& Packing Slips | 3/1/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard | |
| Modificada | Media (5.4) | 0.59% | — | Invoiceninja Invoice Ninja | 24/12/2021 | 17/6/2026 | invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (4.8) | 0.62% | — | Webventures Client Invoicing BY Sprout Invoices | 17/11/2021 | 17/6/2026 | The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.5) | 2.6% | — | Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+32 | 14/7/2021 | 25/8/2026 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR… | |
| Modificada | Media (5.5) | 2.5% | — | Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+28 | 14/7/2021 | 25/8/2026 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. | |
| Modificada | Alta (8.1) | 1.8% | — | Invoiceninja Invoice Ninja | 6/6/2021 | 17/6/2026 | In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net… | |
| Modificada | Alta (7.5) | 1.6% | — | Invoiceplane | 17/5/2021 | 29/7/2026 | In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication. | |
| Modificada | Media (5.3) | 1.2% | — | Invoiceplane | 17/5/2021 | 29/7/2026 | InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable. | |
| Modificada | Media (5.3) | 1.1% | — | Invoiceplane | 10/5/2021 | 29/7/2026 | In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. | |
| Modificada | Media (4.3) | 0.91% | — | Oracle Enterprise Data QualityOracle Retail Invoice MatchingOracle User Management | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management.… | |
| Modificada | Media (4.8) | 0.69% | — | Nchsoftware Express Invoice | 28/12/2020 | 17/6/2026 | NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. | |
| Modificada | Media (5.4) | 0.72% | — | Softrade WP Smart CRM & Invoices | 14/9/2020 | 17/6/2026 | Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and… | |
| Modificada | Alta (7.5) | 1.7% | — | Slicedinvoices Sliced Invoices | 31/8/2020 | 17/6/2026 | Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php. | |
| Modificada | Alta (7.8) | 1.00% | 💥 Exploit | Nchsoftware Express Invoice | 7/4/2020 | 17/6/2026 | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. | |
| Modificada | Alta (8.8) | 2.2% | — | Nchsoftware Express Invoice | 7/4/2020 | 17/6/2026 | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads PDF Invoices | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Invoices | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (5.4) | 0.58% | — | Nchsoftware Express Invoice | 14/10/2019 | 17/6/2026 | In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript. |