Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Payments FOR HubtelAI | 1/10/2026 | 1/10/2026 | The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. | |
| Aplazada | Media (5.3) | 0.18% | — | Payments FOR HubtelAI | 1/10/2026 | 1/10/2026 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. | |
| Aplazada | Media (5.3) | 0.19% | — | Payments FOR HubtelAI | 1/10/2026 | 1/10/2026 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents. | |
| Aplazada | Media (5.3) | 0.29% | — | Deposits AND Partial Payments FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | |
| Aplazada | Crítica (9.1) | 0.45% | — | Zipmoney Payments FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to… | |
| Aplazada | Media (5.3) | 0.30% | — | Accept Stripe PaymentsAI | 5/9/2026 | 8/9/2026 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who… | |
| Aplazada | Media (4.3) | 0.30% | — | Accept Stripe PaymentsAI | 5/9/2026 | 8/9/2026 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing. | |
| Aplazada | Crítica (9.1) | 0.24% | — | Totalpaymentprocessing Total Processing Card PaymentsAI | 29/8/2026 | 31/8/2026 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host… | |
| Aplazada | Alta (7.1) | 0.25% | — | Stripe PaymentsAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | |
| Analizada | Media (6.3) | 0.32% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence:… | |
| Analizada | Alta (8.3) | 0.59% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas,… | |
| Analizada | Alta (8.2) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under verification through an attribution nonce… | |
| Analizada | Alta (8.7) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native).… | |
| Analizada | Alta (8.2) | 0.35% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.7) | 0.33% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in… | |
| Analizada | Alta (7.7) | 0.33% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Payments | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Aplazada | Media (5.3) | 0.16% | — | Fullworksplugins Quick Paypal PaymentsAI | 12/8/2026 | 26/8/2026 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid. | |
| Aplazada | Media (5.3) | 0.31% | — | Mercadopago Mercado Pago Payments FOR WoocommerceAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. | |
| Aplazada | Media (5.3) | 0.40% | — | Woocommerce Paypal PaymentsAI | 1/8/2026 | 29/9/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This… | |
| Aplazada | Media (6.5) | 0.30% | — | Automattic Woocommerce PaymentsAI | 1/8/2026 | 26/8/2026 | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders. | |
| Aplazada | Media (5.3) | 0.30% | — | Direct Payments FOR WoocommerceAI | 1/8/2026 | 26/8/2026 | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,… |