Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.58%—Cedcommerce Refund AND Exchange With RMAAI18/7/202517/6/2026
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible…
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
AnalizadaCrítica (9.6)2.2%—Zohocorp Manageengine Exchange Reporter Plus9/6/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
AplazadaMedia (5.3)0.45%—Jammy928 Coinexchange Cryptoexchange JavaAI18/5/202517/6/2026
A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. This affects the function uploadLocalImage of the file /CoinExchange_CryptoExchange_Java-master/00_framework/core/src/main/java/com/bizzan/bitrade/util/UploadFileUtil.java…
AplazadaAlta (7.1)0.15%—Bundgaard Martins Free Monetized AD Exchange NetworkAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6.
AplazadaMedia (6.5)0.36%—Leartes TRY Exchange RatesAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leartes.NET Leartes TRY Exchange Rates leartes-try-exchange-rates allows Stored XSS.This issue affects Leartes TRY Exchange Rates: from n/a through <= 2.1.
AplazadaMedia (4.3)0.40%—Falselight Exchange RatesAI27/3/202517/6/2026
Missing Authorization vulnerability in falselight Exchange Rates exchange-rates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Exchange Rates: from n/a through <= 1.2.2.
AnalizadaMedia (5.4)0.31%—Wpswings Return Refund AND Exchange FOR Woocommerce14/2/202517/6/2026
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This…
AnalizadaAlta (7.5)0.47%—Wpswings Return Refund AND Exchange FOR Woocommerce14/2/202517/6/2026
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers…
AplazadaAlta (7.1)0.21%—Wpfactory WP Currency Exchange RatesAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through <= 1.2.0.
AplazadaAlta (8.8)0.16%—Netcloud Exchange ClientAI28/11/202417/6/2026
The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been…
AplazadaMedia (5.5)0.37%—Kion Computer Kion Exchange Programs SoftwareAI21/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS. This issue affects KION Exchange Programs Software: before 1.21.9092.29966.
AnalizadaAlta (7.5)8.5%—Microsoft Exchange Server12/11/202417/6/2026
Microsoft Exchange Server Spoofing Vulnerability
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Exchange Reporter Plus5/11/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
AnalizadaAlta (8.1)2.0%—Zohocorp Manageengine Exchange Reporter Plus30/8/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Exchange Reporter Plus26/7/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Exchange Reporter Plus26/7/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.
AplazadaMedia (6.5)0.34%—Currencyrate Exchange Rates WidgetAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Exchange Rates Widget allows Stored XSS.This issue affects Exchange Rates Widget: from n/a through 1.4.0.
AnalizadaAlta (8.8)6.8%—Microsoft Exchange Server12/3/202417/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
AnalizadaAlta (8.8)5.0%—Zohocorp Manageengine Exchange Reporter Plus16/2/202417/6/2026
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
AnalizadaCrítica (9.8)13%⚠ Explotación activa💥 PoCMicrosoft Exchange Server13/2/202417/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaMedia (5.4)0.30%—Currencywiki Currency Converter Widget - Exchange Rates21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Currency.Wiki Currency Converter Widget – Exchange Rates allows Stored XSS.This issue affects Currency Converter Widget – Exchange Rates: from n/a through 3.0.2.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (8)4.9%—Microsoft Exchange Server14/11/202317/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
Orbitaley — Vulnerabilidades