Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2764▲ 64 respecto a la semana anterior
Críticas / altas1288▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

2505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202614/8/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202614/8/2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)2.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
ModificadaAlta (8)0.69%💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/20262/9/2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202614/8/2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AplazadaBaja (3.7)0.24%—Accept Paypal Stripe With Subscriptions FOR WoocommerceAI10/8/202626/8/2026
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal…
AplazadaMedia (5.3)0.29%—Accept Paypal Stripe With Subscriptions FOR WoocommerceAI10/8/202626/8/2026
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full…
AplazadaMedia (5.9)0.16%—Subscriptions FOR WoocommerceAI7/8/202626/8/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without…
AplazadaAlta (8.8)0.64%—Subscriptions FOR WoocommerceAI7/8/202626/8/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack…
AplazadaMedia (4.3)0.27%—Subscriptions FOR WoocommerceAI7/8/202626/8/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that…
AnalizadaAlta (8.5)0.35%—Escriptorium6/8/202618/8/2026
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST…
AnalizadaAlta (7.1)0.41%—Escriptorium6/8/202618/8/2026
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in…
AnalizadaMedia (4.3)0.36%—Escriptorium6/8/202618/8/2026
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room…
AnalizadaMedia (6.5)0.39%—Escriptorium6/8/202618/8/2026
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose…
AnalizadaAlta (8.8)0.53%—Escriptorium6/8/202618/8/2026
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the…
AplazadaMedia (5.3)0.33%—Custom CSS AND JavascriptAI6/8/202612/8/2026
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Pendiente de análisisAlta (8.8)0.64%—Jenkins Multijob PluginAIJenkins Script Security PluginAI5/8/202631/8/2026
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
AplazadaMedia (5.4)0.29%—Cozmoslabs Paid Membership SubscriptionsAI4/8/202626/8/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its…
AplazadaAlta (8.8)0.81%—Subscriptions FOR WoocommerceAI1/8/202612/8/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only…
AplazadaMedia (5.1)0.55%—Phpjabbers PHP Poll ScriptAI31/7/202628/8/2026
A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1.
AplazadaAlta (8.6)0.38%—Phpjabbers PHP Poll ScriptAI31/7/202628/8/2026
A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.
AplazadaCrítica (9.3)0.44%—Phpjabbers CAR Rental ScriptAI31/7/202629/9/2026
Una vulnerabilidad de inyección SQL ha sido identificada en PHP Jabbers - Car Rental Script. La neutralización inadecuada de la entrada proporcionada por el usuario en los parámetros responsables de las funciones de ordenación permite a un atacante no autenticado realizar ataques de inyección SQL. Este problema fue…
AplazadaBaja (3.7)0.28%—Cozmoslabs Paid Membership SubscriptionsAI31/7/202626/8/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
AplazadaMedia (4.3)0.27%—Cozmoslabs Paid Membership SubscriptionsAI31/7/202626/8/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier.