Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▲ 64 respecto a la semana anterior
Críticas / altas1288▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 2.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | |
| Modificada | Alta (8) | 0.69% | 💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 2/9/2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Baja (3.7) | 0.24% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal… | |
| Aplazada | Media (5.3) | 0.29% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full… | |
| Aplazada | Media (5.9) | 0.16% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without… | |
| Aplazada | Alta (8.8) | 0.64% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack… | |
| Aplazada | Media (4.3) | 0.27% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that… | |
| Analizada | Alta (8.5) | 0.35% | — | Escriptorium | 6/8/2026 | 18/8/2026 | Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST… | |
| Analizada | Alta (7.1) | 0.41% | — | Escriptorium | 6/8/2026 | 18/8/2026 | Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in… | |
| Analizada | Media (4.3) | 0.36% | — | Escriptorium | 6/8/2026 | 18/8/2026 | Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room… | |
| Analizada | Media (6.5) | 0.39% | — | Escriptorium | 6/8/2026 | 18/8/2026 | Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose… | |
| Analizada | Alta (8.8) | 0.53% | — | Escriptorium | 6/8/2026 | 18/8/2026 | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the… | |
| Aplazada | Media (5.3) | 0.33% | — | Custom CSS AND JavascriptAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins Multijob PluginAIJenkins Script Security PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. | |
| Aplazada | Media (5.4) | 0.29% | — | Cozmoslabs Paid Membership SubscriptionsAI | 4/8/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its… | |
| Aplazada | Alta (8.8) | 0.81% | — | Subscriptions FOR WoocommerceAI | 1/8/2026 | 12/8/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only… | |
| Aplazada | Media (5.1) | 0.55% | — | Phpjabbers PHP Poll ScriptAI | 31/7/2026 | 28/8/2026 | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1. | |
| Aplazada | Alta (8.6) | 0.38% | — | Phpjabbers PHP Poll ScriptAI | 31/7/2026 | 28/8/2026 | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Phpjabbers CAR Rental ScriptAI | 31/7/2026 | 29/9/2026 | Una vulnerabilidad de inyección SQL ha sido identificada en PHP Jabbers - Car Rental Script. La neutralización inadecuada de la entrada proporcionada por el usuario en los parámetros responsables de las funciones de ordenación permite a un atacante no autenticado realizar ataques de inyección SQL. Este problema fue… | |
| Aplazada | Baja (3.7) | 0.28% | — | Cozmoslabs Paid Membership SubscriptionsAI | 31/7/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present. | |
| Aplazada | Media (4.3) | 0.27% | — | Cozmoslabs Paid Membership SubscriptionsAI | 31/7/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier. |