Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)8.1%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition10/2/202617/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.3)0.80%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/12/202517/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/12/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.5)0.39%—Fabian Currency Exchange System8/12/202517/6/2026
A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the…
AnalizadaMedia (5.5)0.39%—Fabian Currency Exchange System8/12/202517/6/2026
A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.39%—Fabian Currency Exchange System8/12/202517/6/2026
A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.39%—Fabian Currency Exchange System8/12/202517/6/2026
A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
AplazadaMedia (5.4)0.17%—Wpswings Return Refund AND Exchange FOR WoocommerceAI21/11/202517/6/2026
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the wps_rma_fetch_order_msgs() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.19%—Wpswings Return Refund AND Exchange FOR WoocommerceAI21/11/20251/10/2026
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers,…
AnalizadaMedia (6.1)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.
AnalizadaMedia (5.4)0.45%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.
AnalizadaMedia (5.4)0.45%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.
AnalizadaMedia (6.5)1.1%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.
AnalizadaAlta (8.8)0.83%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
AplazadaMedia (6.5)0.21%—Falselight Exchange RatesAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Exchange Rates exchange-rates allows Stored XSS.This issue affects Exchange Rates: from n/a through <= 1.2.5.
AnalizadaAlta (7.5)1.3%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.3)0.87%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.3)0.89%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.4%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalizadaAlta (8)7.7%💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition6/8/202517/6/2026
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security…
Orbitaley — Vulnerabilidades