Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. The manipulation of the argument Client Name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The manipulation of the argument client name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed… | |
| Modificada | Media (4.4) | 0.18% | — | Fortinet Forticamera FirmwareFortinet FortimailFortinet FortindrFortinet Fortirecorder+1 | 12/8/2025 | 17/6/2026 | Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions,… | |
| Aplazada | Media (4.3) | 0.16% | — | Edgarrojas Woo-pdf-invoice-builderAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Cross Site Request Forgery.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.148. | |
| Analizada | Media (6.7) | 0.18% | — | Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+4 | 4/6/2025 | 17/6/2026 | A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An… | |
| Aplazada | Media (6.2) | 0.08% | — | Transsion AivoiceassistantAI | 15/5/2025 | 17/6/2026 | Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage. | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa💥 PoC | Fortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+1 | 13/5/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,… | |
| Aplazada | Alta (7.6) | 0.43% | — | Add-ons.org PDF Invoice Builder FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce allows SQL Injection.This issue affects PDF Invoice Builder for WooCommerce: from n/a through <= 5.3.8. | |
| Aplazada | Alta (8.8) | 0.19% | — | Webappick ChallanAIWebappick PDF Invoice FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Challan: from n/a through <= 3.7.58. | |
| Analizada | Alta (8.9) | 1.0% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , if model_name contains the string… | |
| Analizada | Alta (8.9) | 1.0% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , a new instance of AudioPre class is… | |
| Analizada | Alta (8.9) | 0.95% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load the model on that… | |
| Analizada | Alta (8.9) | 0.95% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user input (e.g. a path to a model) and pass it to the merge function in process_ckpt.py, which uses them to load the models… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info function in process_ckpt.py, which uses it to load the model on… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to the extract_small_model function in process_ckpt.py, which uses it to load the… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable takes user input (e.g. a path to a model) and passes it to the show_info function in process_ckpt.py, which uses it to load the model on… | |
| Analizada | Alta (8.9) | 0.99% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to change_info_ function, which opens and reads the file on the given path (except it… | |
| Analizada | Alta (8.9) | 2.2% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user input and pass it to the click_train function, which concatenates them into a command that is run on the server. This… | |
| Analizada | Alta (8.9) | 2.4% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 and f0method8 take user input and pass it into the extract_f0_feature function, which concatenates them into a command that is run on the… | |
| Analizada | Alta (8.9) | 2.2% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 take user input and pass it to the preprocess_dataset function, which concatenates them into a command that is run on… | |
| Aplazada | Crítica (9.4) | 0.53% | — | Ready InvoicesAI | 16/4/2025 | 17/6/2026 | Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks. | |
| Analizada | Alta (7.5) | 0.39% | — | Fortinet FortiwebFortinet FortivoiceFortinet FortiproxyFortinet Fortios+2 | 8/4/2025 | 17/6/2026 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through… | |
| Analizada | Alta (7.5) | 0.50% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortiosFortinet Fortiproxy+2 | 8/4/2025 | 17/6/2026 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15,… | |
| Aplazada | Media (5.3) | 0.39% | — | Slicedinvoices Sliced InvoicesAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliced Invoices: from n/a through <= 3.10.0. | |
| Analizada | Crítica (9.8) | 0.69% | — | Invoiceplane | 28/3/2025 | 17/6/2026 | InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller. |