Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.45%—Price Drop Alert FOR WOO CommerceAI18/9/202618/9/2026
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
AplazadaAlta (8.8)0.42%—Oracle AlertAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert. Successful attacks of this…
AplazadaAlta (8.1)0.35%—Oracle AlertAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert. Successful attacks of this…
AplazadaMedia (5.4)0.18%—Basecamp UprightAIPrometheusAIPrometheus AlertmanagerAI13/8/20268/9/2026
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as…
AplazadaCrítica (9.8)0.48%—Cozyvision SMS Alert Order NotificationsAI13/8/202614/8/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Pendiente de análisisAlta (8.6)0.58%—Amazon OpensearchAIAmazon Opensearch AlertingAI12/8/202613/8/2026
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
AplazadaAlta (7.5)0.41%—SMS AlertAI2/8/202626/8/2026
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An…
AplazadaMedia (4.4)0.52%—SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack…
AplazadaMedia (4.9)0.48%—SMS AlertAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaMedia (4.9)0.44%—SMS AlertAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
AplazadaCrítica (9.8)0.89%—SMS AlertAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a…
AplazadaAlta (7.1)0.13%—Popup FOR CF7 With Sweet AlertAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
AplazadaMedia (6.5)0.37%—Multvendorx Woocommerce Product Stock AlertAI23/7/202623/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
AplazadaCrítica (9.8)0.48%—Cozyvision SMS Alert Order NotificationsAI23/7/202623/7/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
AplazadaCrítica (9.8)2.2%—SMS AlertAI1/7/20261/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like…
AnalizadaAlta (8.8)0.49%—Weborange Price Alert19/6/202619/8/2026
Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to…
AplazadaAlta (7.5)0.48%—Cozyvision SMS Alert Order NotificationsAI17/6/202617/6/2026
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
AplazadaCrítica (9.8)0.56%—Pi.alertAI27/5/202617/6/2026
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into pialert.conf without validation. Since pialert.conf is loaded via Python's exec() every 3–5 minutes by the…
AplazadaCrítica (9.8)1.0%—PI AlertAI27/5/202617/6/2026
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file via Python's exec(), injected code executes as the daemon process. With…
AplazadaAlta (8.7)0.44%—Pi.alertAI27/5/202620/7/2026
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devices.php route accepts requests from unauthenticated users when the action URL parameter is set to getDevicesTotals. The…
AplazadaAlta (8.4)0.47%—Taiko Ag1000-01a SMS Alert GatewayAI20/5/202623/7/2026
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields. Attackers can bypass…
AnalizadaMedia (6.9)0.59%—Alerta Project Alerta31/3/202624/7/2026
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0.
AplazadaMedia (5.4)0.29%—Cozyvision SMS Alert Order NotificationsAI13/3/202617/6/2026
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.9.0.
AnalizadaAlta (8.8)1.7%—Algosolutions 8180 IP Audio Alerter Firmware23/1/202617/6/2026
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaAlta (8.8)1.5%—Algosolutions 8180 IP Audio Alerter Firmware23/1/202617/6/2026
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the…