Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.08% | — | Samsung Visual Voicemail | 9/9/2026 | 23/9/2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. | |
| Aplazada | Alta (7.5) | 0.53% | — | Invoiceninja Invoice NinjaAI | 4/9/2026 | 9/9/2026 | An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | |
| Aplazada | Media (6.5) | 0.35% | — | SolidinvoiceAI | 4/9/2026 | 10/9/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue. | |
| Aplazada | Alta (7.5) | 0.45% | — | SolidinvoiceAI | 4/9/2026 | 10/9/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized… | |
| Aplazada | Media (5.9) | 0.37% | — | SolidinvoiceAI | 4/9/2026 | 10/9/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP… | |
| Aplazada | Media (6.8) | 0.32% | — | SolidinvoiceAI | 4/9/2026 | 10/9/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a… | |
| Aplazada | Baja (2.1) | 0.35% | — | Invoiceninja Invoice NinjaAI | 1/9/2026 | 2/9/2026 | A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the argument notes leads to server-side request forgery. It is possible to… | |
| Aplazada | Baja (2.1) | 0.38% | — | Invoiceninja Invoice NinjaAI | 1/9/2026 | 1/9/2026 | A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The… | |
| Aplazada | Media (6.5) | 0.87% | — | Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI | 23/8/2026 | 24/8/2026 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (8.8) | 0.52% | — | PropovoiceAI | 15/8/2026 | 20/8/2026 | The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and… | |
| Aplazada | Media (5.1) | 0.31% | — | National Institute OF Information AND Communications Technology VoicetraAI | 13/8/2026 | 28/8/2026 | VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display… | |
| Aplazada | Alta (8.7) | 0.35% | — | InvoiceninjaAILaravelAI | 5/8/2026 | 26/8/2026 | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. | |
| Aplazada | Crítica (9.3) | 0.69% | — | Softvc Vits Singing Voice ConversionAI | 23/7/2026 | 23/7/2026 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated… | |
| Aplazada | Alta (7.2) | 0.27% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13. | |
| Aplazada | Media (6.5) | 0.37% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/7/2026 | 21/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8. | |
| Aplazada | Media (4.3) | 0.39% | — | Wpdesk PDF Invoices Packing Slips FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.47% | — | Invoice123AI | 10/7/2026 | 10/7/2026 | The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.52% | — | Easy InvoiceAI | 9/7/2026 | 9/7/2026 | The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped nonce that is rendered… | |
| Analizada | Media (6.1) | 0.47% | — | Microsoft Dynamics 365 Customer Voice | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.29% | — | Invoiceninja Invoice NinjaAI | 30/6/2026 | 14/7/2026 | Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an… | |
| Aplazada | Crítica (9.8) | 0.80% | — | Invoice GeneratorAI | 27/6/2026 | 29/6/2026 | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and… |