Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 8.1% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 10/2/2026 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.3) | 0.80% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/12/2025 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/12/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Currency Exchange System | 8/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.4) | 0.17% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the wps_rma_fetch_order_msgs() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 21/11/2025 | 1/10/2026 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.1) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option. | |
| Analizada | Media (6.5) | 1.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. | |
| Analizada | Alta (8.8) | 0.83% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/10/2025 | 17/6/2026 | Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/10/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/10/2025 | 17/6/2026 | Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.21% | — | Falselight Exchange RatesAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Exchange Rates exchange-rates allows Stored XSS.This issue affects Exchange Rates: from n/a through <= 1.2.5. | |
| Analizada | Alta (7.5) | 1.3% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.3) | 0.87% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.3) | 0.89% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analizada | Alta (8) | 7.7% | 💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 6/8/2025 | 17/6/2026 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security… |