Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.58% | — | Cedcommerce Refund AND Exchange With RMAAI | 18/7/2025 | 17/6/2026 | The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible… | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. | |
| Analizada | Crítica (9.6) | 2.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. | |
| Aplazada | Media (5.3) | 0.45% | — | Jammy928 Coinexchange Cryptoexchange JavaAI | 18/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. This affects the function uploadLocalImage of the file /CoinExchange_CryptoExchange_Java-master/00_framework/core/src/main/java/com/bizzan/bitrade/util/UploadFileUtil.java… | |
| Aplazada | Alta (7.1) | 0.15% | — | Bundgaard Martins Free Monetized AD Exchange NetworkAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6. | |
| Aplazada | Media (6.5) | 0.36% | — | Leartes TRY Exchange RatesAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leartes.NET Leartes TRY Exchange Rates leartes-try-exchange-rates allows Stored XSS.This issue affects Leartes TRY Exchange Rates: from n/a through <= 2.1. | |
| Aplazada | Media (4.3) | 0.40% | — | Falselight Exchange RatesAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in falselight Exchange Rates exchange-rates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Exchange Rates: from n/a through <= 1.2.2. | |
| Analizada | Media (5.4) | 0.31% | — | Wpswings Return Refund AND Exchange FOR Woocommerce | 14/2/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This… | |
| Analizada | Alta (7.5) | 0.47% | — | Wpswings Return Refund AND Exchange FOR Woocommerce | 14/2/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wpfactory WP Currency Exchange RatesAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through <= 1.2.0. | |
| Aplazada | Alta (8.8) | 0.16% | — | Netcloud Exchange ClientAI | 28/11/2024 | 17/6/2026 | The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been… | |
| Aplazada | Media (5.5) | 0.37% | — | Kion Computer Kion Exchange Programs SoftwareAI | 21/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS. This issue affects KION Exchange Programs Software: before 1.21.9092.29966. | |
| Analizada | Alta (7.5) | 8.5% | — | Microsoft Exchange Server | 12/11/2024 | 17/6/2026 | Microsoft Exchange Server Spoofing Vulnerability | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Exchange Reporter Plus | 5/11/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module. | |
| Analizada | Alta (8.1) | 2.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/8/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. | |
| Modificada | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/7/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module. | |
| Modificada | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/7/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module. | |
| Aplazada | Media (6.5) | 0.34% | — | Currencyrate Exchange Rates WidgetAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Exchange Rates Widget allows Stored XSS.This issue affects Exchange Rates Widget: from n/a through 1.4.0. | |
| Analizada | Alta (8.8) | 6.8% | — | Microsoft Exchange Server | 12/3/2024 | 17/6/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 5.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 16/2/2024 | 17/6/2026 | Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature. | |
| Analizada | Crítica (9.8) | 13% | ⚠ Explotación activa💥 PoC | Microsoft Exchange Server | 13/2/2024 | 17/6/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 0.30% | — | Currencywiki Currency Converter Widget - Exchange Rates | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Currency.Wiki Currency Converter Widget – Exchange Rates allows Stored XSS.This issue affects Currency Converter Widget – Exchange Rates: from n/a through 3.0.2. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Alta (8) | 4.9% | — | Microsoft Exchange Server | 14/11/2023 | 17/6/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability |