Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.30% | — | BSV Wallet ToolboxAIBSV Wallet Toolbox ClientAIBSV Wallet Toolbox MobileAI | 24/9/2026 | 30/9/2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created… | |
| Aplazada | Crítica (9.3) | 0.37% | — | YptwalletAIWwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Wallet FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value. | |
| Aplazada | Media (5.9) | 0.29% | — | Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily… | |
| Aplazada | Media (4.3) | 0.49% | — | Wallet FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 29/6/2026 | 29/6/2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | |
| Aplazada | Alta (7.1) | 0.37% | — | Wpswings Wallet System FOR WoocommerceAI | 2/6/2026 | 22/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5. | |
| Aplazada | Media (5.6) | 0.08% | — | Oppo WalletAI | 27/4/2026 | 17/6/2026 | OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information disclosure. | |
| Analizada | Alta (8.1) | 0.20% | — | Sgbett Bsv-walletSgbett BSV Ruby SDK | 9/4/2026 | 17/6/2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier's signature over the certificate contents. In acquisition_protocol: 'direct', the caller supplies all certificate fields… | |
| Aplazada | Media (6.5) | 0.28% | — | Subrata MAL Terawallet - FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Subrata Mal TeraWallet – For WooCommerce woo-wallet allows Leveraging Race Conditions.This issue affects TeraWallet – For WooCommerce: from n/a through <= 1.5.15. | |
| Analizada | Alta (7.5) | 0.40% | — | Trustwallet Trust Wallet Core | 20/1/2026 | 17/6/2026 | A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Media (6.5) | 0.25% | — | Wpswings Wallet System FOR WoocommerceAI | 17/1/2026 | 17/6/2026 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'change_wallet_fund_request_status_callback' function in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.3) | 0.20% | — | Wpswings Wallet System FOR WoocommerceAI | 5/1/2026 | 30/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through <= 2.7.3. | |
| Aplazada | Baja (1.9) | 0.13% | — | Boquan DotwalletAI | 4/8/2025 | 17/6/2026 | A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.boquanhash.dotwallet. The manipulation leads to improper export of android application components. The attack… | |
| Aplazada | Media (4.3) | 0.13% | — | Wpswings Wallet System FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Cross Site Request Forgery.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.7. | |
| Aplazada | Media (5.7) | 0.22% | — | Trustwallet Trust WalletAI | 1/7/2025 | 17/6/2026 | Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpswings Wallet System FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Reflected XSS.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.8. | |
| Analizada | Media (4.3) | 0.25% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to increase their own wallet balance,… | |
| Analizada | Media (4.3) | 0.15% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it… | |
| Aplazada | Alta (7.1) | 0.33% | — | Dashed-slug Bitcoin AND Altcoin WalletsAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashed-slug.net Bitcoin and Altcoin Wallets wallets allows Reflected XSS.This issue affects Bitcoin and Altcoin Wallets: from n/a through <= 6.3.1. | |
| Aplazada | Media (6.5) | 0.46% | — | Hemnathmouli WC WalletAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in hemnathmouli WC Wallet wc-wallet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WC Wallet: from n/a through <= 2.2.0. | |
| Aplazada | Crítica (9.3) | 0.77% | — | Walletstation Code Generator PROAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation Code Generator Pro code-generator-pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through <= 1.2. | |
| Analizada | Media (6.5) | 0.50% | — | Standalonetech Terawallet | 28/11/2024 | 17/6/2026 | The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpswings Wallet System FOR WoocommerceAI | 13/8/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13. |