Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

499 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.50%—Fortinet FortimailFortinet FortiddosFortinet FortivoiceFortinet Fortirecorder+128/3/202517/6/2026
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0,…
AplazadaCrítica (9.8)0.68%—Convivance StandvoiceAI25/3/202517/6/2026
SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.
AplazadaMedia (5.4)0.18%—Speakpipe Voicemail FOR WebsitesAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SpeakPipe SpeakPipe speakpipe-voicemail-for-websites allows Cross Site Request Forgery.This issue affects SpeakPipe: from n/a through <= 0.2.
AplazadaMedia (5.9)0.54%—Powerpack Print Invoice Delivery NotesAI8/3/202517/6/2026
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the…
AnalizadaAlta (7.1)0.62%💥 ExploitThedevoice Lazy Blocks26/2/202517/6/2026
The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (5.3)0.48%—Peprodev Ultimate Invoice19/2/202517/6/2026
The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which…
AnalizadaAlta (7.5)0.66%—Audiocodes ONE Voice Operations Center7/2/202517/6/2026
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.
AnalizadaMedia (6.1)0.24%—Audiocodes ONE Voice Operations Center7/2/202517/6/2026
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.
AnalizadaAlta (7.5)0.36%—Audiocodes ONE Voice Operations Center7/2/202517/6/2026
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.
AnalizadaMedia (6.3)0.45%—Wpovernight Woocommerce PDF Invoices& Packing Slips4/2/202517/6/2026
woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized users to access any PDF document from a store if they: 1. Have access to a guest document link and 2. Replace the…
AplazadaMedia (6.4)0.27%—Webventures Client Invoicing BY Sprout InvoicesAI27/1/202517/6/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.1.
AplazadaMedia (6.5)0.30%—Add-ons.org PDF Invoice Builder FOR WoocommerceAI24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce allows Stored XSS.This issue affects PDF Invoice Builder for WooCommerce: from n/a through <= 4.6.0.
ModificadaMedia (4.8)0.36%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips,…
ModificadaMedia (6.1)0.45%—Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+1022/1/202517/6/2026
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
AnalizadaCrítica (9.1)0.60%—IBM Voice Gateway18/1/202517/6/2026
IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, which would allow them to attacker to view or modify information in the XML document.
ModificadaCrítica (9.1)0.79%—Fortinet FortirecorderFortinet FortivoiceFortinet Fortiweb16/1/20258/7/2026
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4,…
AplazadaAlta (7.7)0.40%—Invoiceninja Invoice NinjaAI14/1/202514/7/2026
Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
ModificadaCrítica (9.1)15%—Fortinet FortimanagerFortinet Fortimanager CloudFortinet FortiproxyFortinet Fortirecorder+314/1/20258/7/2026
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15,…
AnalizadaMedia (6.7)0.63%—Fortinet Fortivoice14/1/202517/6/2026
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
AnalizadaAlta (8.8)0.80%—Fortinet Fortivoice14/1/202517/6/2026
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via sending crafted HTTP or HTTPS requests
AplazadaAlta (8.8)6.7%💥 ExploitInvoiceninja Invoice NinjaAI7/1/202517/6/2026
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client.php file can be…
AplazadaCrítica (9.8)44%💥 ExploitCrater InvoiceAILaravelAI7/1/202517/6/2026
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies…
AplazadaAlta (7.5)0.61%—Service Shogun ACH Invoice APPAI7/1/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App ach-invoice-app allows PHP Local File Inclusion.This issue affects Ach Invoice App: from n/a through <= 1.0.1.
AplazadaMedia (4.3)0.28%—Print Invoice AND Delivery Notes FOR WoocommerceAI24/12/202417/6/2026
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaMedia (6.3)0.53%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known…