Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.14% | — | Razorpay FOR WoocommerceAI | 4/10/2026 | 4/10/2026 | The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders. | |
| Aplazada | Media (5.4) | 0.10% | — | Razorpay Payment Links FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Razorpay Payment ButtonAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Razorpay FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Knitpay Razorpay Payment Links FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4. | |
| Modificada | Baja (2.7) | 0.32% | — | Razormist Basic Library System | 13/4/2026 | 17/6/2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Razormist Basic Library System | 13/4/2026 | 17/6/2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Razormist Basic Library System | 13/4/2026 | 17/6/2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php. | |
| Aplazada | Media (5.3) | 0.29% | — | Razorpay FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommerce: from n/a through <= 4.8.2. | |
| Aplazada | Media (5.3) | 0.37% | — | Razorpay FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback always returning true, providing no actual… | |
| Analizada | Baja (2.1) | 0.40% | — | Razormist Online Polling System | 17/9/2025 | 25/9/2026 | A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Baja (2) | 0.25% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.54% | — | Razormist Online Polling System | 30/8/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed from a remote location. The exploit is now public and may be used. | |
| Analizada | Baja (1.9) | 0.34% | — | Razormist Student Result Management System | 22/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/admin/system of the component System Settings Page. The manipulation of the argument School Name leads to cross site… | |
| Analizada | Baja (1.9) | 0.30% | — | Razormist Student Result Management System | 22/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/admin/manage_students of the component Manage Students Module. The manipulation leads to cross site scripting. The attack may be initiated… | |
| Analizada | Baja (1.9) | 0.33% | — | Razormist Student Result Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/announcement of the component Announcement Page. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate… | |
| Analizada | Baja (1.9) | 0.33% | — | Razormist Student Result Management System | 6/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /script/academic/division-system of the component Division System Page. The manipulation of the argument Division leads to cross site… | |
| Analizada | Baja (1.9) | 0.34% | — | Razormist Student Result Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation leads to cross site scripting. It is possible to initiate the… | |
| Analizada | Media (6.9) | 0.59% | — | Razormist Student Result Management System | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (6.9) | 0.48% | — | Razormist Health Center Patient Record Management System | 31/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Health Center Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient.php. The manipulation of the argument itr_no leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.9) | 0.52% | — | Razormist Health Center Patient Record Management System | 31/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin.php. The manipulation of the argument Username leads to sql injection. The attack may be launched… |