Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/12/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.3) | 0.17% | — | Subscriptions Memberships FOR PaypalAI | 22/11/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries… | |
| Aplazada | Media (5.3) | 0.22% | — | Scott Paterson Subscriptions AND Memberships FOR PaypalAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.2) | 0.36% | — | Easy Email SubscriptionAI | 12/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (4.3) | 0.12% | — | Easy Email SubscriptionAI | 6/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a… | |
| Aplazada | Media (4.9) | 0.28% | — | Easy Email SubscriptionAI | 6/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.23% | — | Cozmoslabs Paid Membership SubscriptionsAI | 5/11/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and… | |
| Aplazada | Media (5.9) | 0.29% | — | I13websolution Email Subscription PopupAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nks Email Subscription Popup email-subscribe allows Stored XSS.This issue affects Email Subscription Popup: from n/a through <= 1.2.26. | |
| Analizada | Alta (8.8) | 0.83% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/10/2025 | 17/6/2026 | Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/10/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/10/2025 | 17/6/2026 | Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Media (4.3) | 0.19% | — | Wpshuffle WP Subscription Forms PROAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO wp-subscription-forms-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms PRO: from n/a through <= 2.0.5. | |
| Analizada | Alta (7.5) | 0.39% | — | Web3js Web3-core-subscriptions | 24/9/2025 | 17/6/2026 | The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service… | |
| Aplazada | Media (6.5) | 0.28% | — | Zoho SubscriptionsAIZoho BillingAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing zoho-subscriptions allows DOM-Based XSS.This issue affects Zoho Billing: from n/a through <= 4.1. | |
| Aplazada | Media (5.3) | 0.35% | — | Cozmoslabs Paid Member SubscriptionsAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9. | |
| Aplazada | Alta (7.1) | 0.12% | — | Nonletter Newsletter Subscription Widget FOR SendblasterAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module newsletter-subscription-widget-for-sendblaster allows Stored XSS.This issue affects Newsletter subscription optin module: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.5) | 0.56% | — | Cozmoslabs Paid Member SubscriptionsAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows PHP Local File Inclusion.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.4. | |
| Analizada | Alta (7.5) | 1.3% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.3) | 0.87% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.3) | 0.89% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analizada | Alta (8) | 7.7% | 💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 6/8/2025 | 17/6/2026 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security… | |
| Analizada | Media (6.5) | 0.27% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 9/7/2025 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcfm_redirect_to_setup function in all versions up to, and including, 6.7.16. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.27% | — | Cozmoslabs Paid Member SubscriptionsAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows SQL Injection.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Storepro Subscription Renewal Reminders FOR WoocommerceAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce subscriptions-renewal-reminders allows Cross Site Request Forgery.This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through <= 1.4.1. |