Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.63%—Paysafe Barzahlen Payment Module PHP SDK8/1/202317/6/2026
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be…
ModificadaMedia (6.1)0.78%—Wechat-php-sdk Project Wechat-php-sdk17/12/202117/6/2026
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
ModificadaMedia (5.9)0.98%—Globalpayments PHP SDK14/2/202017/6/2026
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
ModificadaMedia (6.1)1.2%—Novaksolutions Infusionsoft-php-sdk3/7/201917/6/2026
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
ModificadaMedia (6.1)0.84%—Amazon Payfort-php-sdk14/11/201817/6/2026
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
ModificadaMedia (6.1)0.86%—Amazon Payfort-php-sdk14/11/201817/6/2026
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
ModificadaMedia (6.1)1.5%—Amazon Payfort-php-sdk14/11/201817/6/2026
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
ModificadaMedia (6.1)0.86%—Amazon Payfort-php-sdk14/11/201817/6/2026
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
ModificadaMedia (6.1)0.68%—Amazon Payfort-php-sdk14/11/201817/6/2026
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
Orbitaley — Vulnerabilidades