Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | YaycurrencyAI | 19/8/2026 | 26/8/2026 | The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpml Woocommerce Multilingual AND MulticurrencyAI | 6/8/2026 | 12/8/2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | |
| Analizada | Baja (2.1) | 0.25% | — | Rubyconcurrency Concurrent Ruby | 24/6/2026 | 26/6/2026 | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its… | |
| Analizada | Baja (2) | 0.15% | — | Rubyconcurrency Concurrent Ruby | 24/6/2026 | 26/6/2026 | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low 15 bits are used for the read hold… | |
| Modificada | Alta (8.2) | 0.67% | — | Rubyconcurrency Concurrent Ruby | 24/6/2026 | 5/8/2026 | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compare_and_set(old_value, new_value)… | |
| Aplazada | Media (4.3) | 0.37% | — | FOX Currency Switcher ProfessionalAI | 28/5/2026 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled… | |
| Aplazada | Alta (7.1) | 0.25% | — | Realmag777 Wpcs Currency-switcherAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.4) | 0.32% | — | Cryptocurrency Prijsvergelijking WidgetAI | 27/5/2026 | 17/6/2026 | The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the as_get_coin_shortcode() function, which renders the 'width' (and 'height') shortcode attribute directly into the style attribute of an… | |
| Aplazada | Alta (8.1) | 0.50% | — | FOX Currency Switcher ProfessionalAI | 15/5/2026 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (5.3) | 0.29% | — | Adastracrypto Cryptocurrency Donation BOXAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13. | |
| Aplazada | Media (5.3) | 0.31% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5. | |
| Aplazada | Alta (7.6) | 0.38% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5. | |
| Aplazada | Media (5.3) | 0.26% | — | Woobewoo WBW Currency Switcher FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5. | |
| Aplazada | Alta (7.5) | 0.34% | — | Yaycommerce YaycurrencyAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3. | |
| Aplazada | Alta (7.2) | 0.36% | — | Sell BTC Cryptocurrency Selling CalculatorAI | 31/1/2026 | 17/6/2026 | The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'orderform_data' AJAX action in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.4) | 0.22% | — | FX Currency ConverterAI | 12/12/2025 | 17/6/2026 | The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_convert' shortcode in all versions up to, and including, 0.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.3) | 0.27% | — | Cryptocurrency Payment GatewayAI | 18/11/2025 | 17/6/2026 | The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' function in all versions up to, and including, 2.0.25. This makes it possible for unauthenticated attackers to opt in and out of… | |
| Analizada | Media (4.3) | 0.13% | — | 2bits Currency | 30/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0. | |
| Aplazada | Media (6.5) | 0.20% | — | JOE Open Currency ConverterAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Open Currency Converter artiss-currency-converter allows Stored XSS.This issue affects Open Currency Converter: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.6) | 0.28% | — | Yaycommerce YaycurrencyAI | 26/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affects YayCurrency: from n/a through <= 3.3.1. | |
| Aplazada | Media (6.4) | 0.27% | — | Euro Fxref Currency ConverterAI | 20/6/2025 | 17/6/2026 | The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currency shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… |