Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.15%—Wpswings Points AND Rewards FOR WoocommerceAI23/9/202623/9/2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a…
AplazadaAlta (7.5)0.35%—Wpswings Return Refund AND Exchange FOR WoocommerceAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
AplazadaAlta (7.5)0.26%—Wpswings Ultimate Gift Cards FOR WoocommerceAI10/9/202610/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption…
AplazadaMedia (5.5)0.14%—Wings3dAI9/9/20269/9/2026
An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file
AplazadaMedia (5.3)0.31%—Wpswings Ultimate Gift Cards FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
AplazadaAlta (7.7)0.44%—Pterodactyl WingsAI26/8/20269/9/2026
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down…
AplazadaMedia (6.5)0.27%—Wpswings Return Refund AND Exchange FOR WoocommerceAI26/8/202626/8/2026
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return…
AplazadaMedia (5.3)0.32%—Wpswings Membership FOR WoocommerceAI19/8/202626/8/2026
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the…
AplazadaMedia (6.5)0.34%—Wpswings Wallet System FOR WoocommerceAI12/8/202626/8/2026
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the…
AplazadaAlta (7.5)0.54%—Swingmx Swing MusicAI11/8/202628/8/2026
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use…
AplazadaMedia (5.5)0.41%—Chiuwingyan HouseAI6/8/202612/8/2026
A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaAlta (7.6)0.15%—Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+2074/8/20266/8/2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
AplazadaAlta (7.5)0.61%—Pterodactyl WingsAI31/7/202610/9/2026
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
AplazadaCrítica (9.9)0.51%—Pterodactyl WingsAI31/7/202610/9/2026
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon…
AplazadaMedia (5.5)0.16%—Pterodactyl WingsAI31/7/202610/9/2026
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. This issue is fixed in version 1.13.0.
AplazadaAlta (8.1)0.68%—Pterodactyl PanelAIPterodactyl WingsAI28/7/202630/7/2026
Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel…
AplazadaAlta (8.6)0.53%—Wpswings Membership FOR WoocommerceAI13/7/202613/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.
AplazadaAlta (7.2)0.27%—Wpswings PDF Generator FOR WordpressAI13/7/202613/7/2026
Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.
AplazadaMedia (6.5)0.33%—Wpswings Event Tickets Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.
AnalizadaAlta (7.1)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+496/7/20268/7/2026
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
AplazadaAlta (7.1)0.34%—Wpswings Wallet System FOR WoocommerceAI29/6/202629/6/2026
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
AplazadaAlta (7.1)0.37%—Wpswings Wallet System FOR WoocommerceAI2/6/202622/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.
AnalizadaAlta (7.2)0.10%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+2141/6/202622/7/2026
Memory Corruption when processing fastboot commands to set display mode.
AnalizadaAlta (7.2)0.10%—Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+2691/6/202622/7/2026
Memory corruption while processing fastboot commands with improperly formatted input.
AnalizadaAlta (7.1)0.06%—Qualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 1 Mobile Platform FirmwareQualcomm Smart Audio 400 Platform Firmware+2131/6/202622/7/2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.