Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

182 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Paid Member SubscriptionsAI27/7/202627/7/2026
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
AnalizadaAlta (7.8)2.5%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.6)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AplazadaAlta (7.2)0.27%—Paid Member SubscriptionsAI2/7/20262/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
AplazadaAlta (7.5)0.35%—Subscriptions FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
AplazadaAlta (7.1)0.25%—Paid Member SubscriptionsAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
AnalizadaMedia (5.4)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.1)0.70%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
ModificadaMedia (6.5)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
ModificadaMedia (6.1)0.46%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.1)0.41%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (4.3)0.12%—Convers LAB WpsubscriptionAI25/5/202624/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This issue affects WPSubscription: from n/a through 1.9.1.
AplazadaMedia (4.3)0.20%—Patternsinthecloud Autoship Cloud FOR Woocommerce Subscription ProductsAI25/5/202624/7/2026
Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.
AnalizadaMedia (6.1)0.52%⚠ Explotación activaMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AplazadaAlta (7.5)0.46%—Wpswings Subscriptions FOR WoocommerceAI25/3/202617/6/2026
Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10.
AplazadaAlta (8.6)0.36%—Convers LAB WpsubscriptionAI25/3/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSubscription: from n/a through <= 1.8.10.
AplazadaMedia (5.3)0.31%—Wpswings Subscriptions FOR WoocommerceAI18/3/202617/6/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any…
AplazadaMedia (6.5)0.36%—Cozmoslabs Paid Member SubscriptionsAI20/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8.
AnalizadaMedia (6.5)8.1%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition10/2/202617/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (6.4)0.22%—Mailgun SubscriptionsAI12/12/202517/6/2026
The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_subscription_form' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (5.3)0.80%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/12/202517/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.