Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Paid Member SubscriptionsAI | 27/7/2026 | 27/7/2026 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | |
| Analizada | Alta (7.8) | 2.5% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Aplazada | Alta (7.2) | 0.27% | — | Paid Member SubscriptionsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Subscriptions FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paid Member SubscriptionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. | |
| Analizada | Media (5.4) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.1) | 0.70% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Media (6.5) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | |
| Modificada | Media (6.1) | 0.46% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (4.3) | 0.12% | — | Convers LAB WpsubscriptionAI | 25/5/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This issue affects WPSubscription: from n/a through 1.9.1. | |
| Aplazada | Media (4.3) | 0.20% | — | Patternsinthecloud Autoship Cloud FOR Woocommerce Subscription ProductsAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0. | |
| Analizada | Media (6.1) | 0.52% | ⚠ Explotación activa | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Alta (7.5) | 0.46% | — | Wpswings Subscriptions FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10. | |
| Aplazada | Alta (8.6) | 0.36% | — | Convers LAB WpsubscriptionAI | 25/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSubscription: from n/a through <= 1.8.10. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Subscriptions FOR WoocommerceAI | 18/3/2026 | 17/6/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any… | |
| Aplazada | Media (6.5) | 0.36% | — | Cozmoslabs Paid Member SubscriptionsAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8. | |
| Analizada | Media (6.5) | 8.1% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 10/2/2026 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (6.4) | 0.22% | — | Mailgun SubscriptionsAI | 12/12/2025 | 17/6/2026 | The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_subscription_form' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.80% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/12/2025 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |