Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.19% | — | Iqonic KivicareAI | 1/9/2026 | 1/9/2026 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key. | |
| Aplazada | Media (5.4) | 0.23% | — | Akilli Ticaret Software Technologies LTD E-commerce PackAI | 28/8/2026 | 2/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001. | |
| Aplazada | Media (6.5) | 0.34% | — | Iqonic KivicareAI | 19/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports. | |
| Aplazada | Media (4.3) | 0.27% | — | Iqonic KivicareAI | 19/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. | |
| Aplazada | Media (6.5) | 0.41% | — | Iqonic KivicareAI | 15/8/2026 | 20/8/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Alta (7.5) | 0.41% | — | Iqonic KivicareAI | 13/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data. | |
| Aplazada | Alta (8.8) | 0.43% | — | Iqonic KivicareAI | 12/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection. | |
| Aplazada | Media (4.3) | 0.25% | — | Iqonic KivicareAI | 12/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices and appointment details. | |
| Aplazada | Media (6.5) | 0.41% | — | Iqonic KivicareAI | 11/7/2026 | 15/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.5) | 0.47% | — | Iqonic KivicareAI | 11/7/2026 | 13/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (5.3) | 0.56% | — | Iqonic KivicareAI | 10/7/2026 | 10/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Inrove Software AND Internet Services BieticaretAI | 9/7/2026 | 9/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57. | |
| Aplazada | Media (6.3) | 0.26% | — | Iqonic KivicareAI | 15/6/2026 | 17/6/2026 | Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions. | |
| Aplazada | Alta (8.2) | 0.44% | — | Iqonic KivicareAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0. | |
| Aplazada | Alta (8.8) | 0.45% | — | Gosoft Software Industry AND Trade Proticaret E CommerceAI | 7/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. This issue affects Proticaret E-Commerce: from v5.0.0 before V 6.0.1767.1383. | |
| Analizada | Alta (8.8) | 0.27% | — | Web-ofisi E-ticaret | 26/3/2026 | 17/6/2026 | WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-based, time-based blind, and stacked… | |
| Aplazada | Alta (7.1) | 0.18% | — | Iqonic KivicareAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through <= 3.6.16. | |
| Aplazada | Media (6.5) | 0.19% | — | Iqonic KivicareAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.16. | |
| Aplazada | Alta (8.2) | 0.42% | — | Iqonic KivicareAI | 18/3/2026 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create… | |
| Aplazada | Alta (7.3) | 0.54% | — | Iqonic KivicareAI | 18/3/2026 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for… | |
| Aplazada | Baja (1.1) | 0.13% | — | Albert Saglik Hizmetleri VE Ticaret Albert HealthAI | 16/3/2026 | 17/6/2026 | A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the component Google Cloud Service Account Key Handler. Performing a manipulation results in unprotected storage of credentials.… | |
| Analizada | Alta (8.8) | 0.38% | — | Web-ofisi Platinum E-ticaret | 22/2/2026 | 17/6/2026 | Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send POST requests to the ajax/productsFilterSearch endpoint with malicious 'q' values using time-based blind SQL… | |
| Modificada | Alta (8.8) | 0.38% | — | Web-ofisi Platinum E-ticaret | 22/2/2026 | 17/6/2026 | Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time-based SQL injection techniques to… | |
| Modificada | Alta (8.8) | 0.41% | — | Web-ofisi E-ticaret | 22/2/2026 | 17/6/2026 | Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'a' parameter. Attackers can send GET requests to with malicious 'a' parameter values to extract sensitive database information. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Inrove Software AND Internet Services Bieticaret CMSAI | 19/2/2026 | 17/6/2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this… |