Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Codisto Omnichannel FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codisto Omnichannel for WooCommerce codistoconnect allows Stored XSS.This issue affects Omnichannel for WooCommerce: from n/a through <= 1.3.65. | |
| Aplazada | Alta (7.2) | 0.29% | — | Codisto Omnichannel FOR WoocommerceAI | 4/12/2025 | 17/6/2026 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1.3.65 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.49% | — | Microsoft Dynamics Omnichannel SDK Storage Containers | 20/11/2025 | 17/6/2026 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.1) | 0.31% | — | Xcally OmnichannelAI | 13/11/2025 | 7/10/2026 | Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user… | |
| Modificada | Crítica (9.8) | 1.0% | — | Kerawen Omnichannel Stocks | 7/7/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Conarc Ichannel | 19/12/2017 | 17/6/2026 | Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service). | |
| Modificada | Alta (7.5) | 3.6% | — | Viprinet Multichannel VPN Router 300 Firmware | 20/1/2017 | 17/6/2026 | The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows remote attackers to perform a replay attack. | |
| Modificada | Media (5.9) | 1.7% | — | Viprinet Multichannel VPN Router 300 Firmware | 20/1/2017 | 17/6/2026 | The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack. | |
| Modificada | Media (6.1) | 4.5% | 💥 Exploit | Viprinet Multichannel VPN Router 300 Firmware | 20/1/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in the old interface, (3) username when creating an account in the new… | |
| Modificada | Media (5.4) | 0.27% | — | Wsaudichannelalnas Project Wsaudichannelalnas | 23/9/2014 | 17/6/2026 | The wSaudichannelAlNasr (aka com.wSaudichannelAlNasr) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |