Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

499 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.08%—Samsung Visual Voicemail9/9/202623/9/2026
Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
AplazadaAlta (7.5)0.53%—Invoiceninja Invoice NinjaAI4/9/20269/9/2026
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
AplazadaMedia (6.5)0.35%—SolidinvoiceAI4/9/202610/9/2026
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue.
AplazadaAlta (7.5)0.45%—SolidinvoiceAI4/9/202610/9/2026
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized…
AplazadaMedia (5.9)0.37%—SolidinvoiceAI4/9/202610/9/2026
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP…
AplazadaMedia (6.8)0.32%—SolidinvoiceAI4/9/202610/9/2026
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a…
AplazadaBaja (2.1)0.35%—Invoiceninja Invoice NinjaAI1/9/20262/9/2026
A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the argument notes leads to server-side request forgery. It is possible to…
AplazadaBaja (2.1)0.38%—Invoiceninja Invoice NinjaAI1/9/20261/9/2026
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The…
AplazadaMedia (6.5)0.87%—Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI23/8/202624/8/2026
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (8.8)0.52%—PropovoiceAI15/8/202620/8/2026
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and…
AplazadaMedia (5.1)0.31%—National Institute OF Information AND Communications Technology VoicetraAI13/8/202628/8/2026
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display…
AplazadaAlta (8.7)0.35%—InvoiceninjaAILaravelAI5/8/202626/8/2026
InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.
AplazadaCrítica (9.3)0.69%—Softvc Vits Singing Voice ConversionAI23/7/202623/7/2026
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated…
AplazadaAlta (7.2)0.27%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaAlta (7.1)0.25%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaMedia (6.5)0.27%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaMedia (6.5)0.37%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaMedia (6.5)0.34%—Webventures Client Invoicing BY Sprout InvoicesAI13/7/202613/7/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.
AplazadaMedia (6.5)0.37%—Edgarrojas Woo-pdf-invoice-builderAI13/7/202621/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.
AplazadaMedia (4.3)0.39%—Wpdesk PDF Invoices Packing Slips FOR WoocommerceAI11/7/202613/7/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.47%—Invoice123AI10/7/202610/7/2026
The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AplazadaMedia (5.3)0.52%—Easy InvoiceAI9/7/20269/7/2026
The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped nonce that is rendered…
AnalizadaMedia (6.1)0.47%—Microsoft Dynamics 365 Customer Voice9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (5.3)0.29%—Invoiceninja Invoice NinjaAI30/6/202614/7/2026
Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an…
AplazadaCrítica (9.8)0.80%—Invoice GeneratorAI27/6/202629/6/2026
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and…