Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Wpswings Points AND Rewards FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a… | |
| Aplazada | Alta (7.5) | 0.35% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | |
| Aplazada | Alta (7.5) | 0.26% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption… | |
| Aplazada | Media (5.5) | 0.14% | — | Wings3dAI | 9/9/2026 | 9/9/2026 | An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 2/9/2026 | 2/9/2026 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. | |
| Aplazada | Alta (7.7) | 0.44% | — | Pterodactyl WingsAI | 26/8/2026 | 9/9/2026 | Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 26/8/2026 | 26/8/2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return… | |
| Aplazada | Media (5.3) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 19/8/2026 | 26/8/2026 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Pterodactyl WingsAI | 31/7/2026 | 10/9/2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0. | |
| Aplazada | Crítica (9.9) | 0.51% | — | Pterodactyl WingsAI | 31/7/2026 | 10/9/2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon… | |
| Aplazada | Media (5.5) | 0.16% | — | Pterodactyl WingsAI | 31/7/2026 | 10/9/2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. This issue is fixed in version 1.13.0. | |
| Aplazada | Alta (8.1) | 0.68% | — | Pterodactyl PanelAIPterodactyl WingsAI | 28/7/2026 | 30/7/2026 | Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel… | |
| Aplazada | Alta (8.6) | 0.53% | — | Wpswings Membership FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0. | |
| Aplazada | Alta (7.2) | 0.27% | — | Wpswings PDF Generator FOR WordpressAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpswings Event Tickets Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 29/6/2026 | 29/6/2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | |
| Aplazada | Alta (7.1) | 0.37% | — | Wpswings Wallet System FOR WoocommerceAI | 2/6/2026 | 22/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5. | |
| Aplazada | Crítica (10) | 0.52% | — | Wpswings Gift Cards FOR Woocommerce PROAI | 20/5/2026 | 23/7/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6. | |
| Aplazada | Alta (7.5) | 0.46% | — | Wpswings Subscriptions FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Subscriptions FOR WoocommerceAI | 18/3/2026 | 17/6/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any… | |
| Aplazada | Media (5.3) | 0.22% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4. | |
| Analizada | Alta (7.8) | 0.20% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Alta (7.8) | 0.20% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Alta (7.8) | 0.20% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. |