Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)4.1%—Microsoft Exchange Server14/2/202319/8/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
AnalizadaAlta (8.8)59%⚠ Explotación activaMicrosoft Exchange Server14/2/202319/8/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaAlta (7.5)3.2%—Zohocorp Manageengine Exchange Reporter Plus17/1/202317/6/2026
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
ModificadaAlta (7.8)0.57%—Microsoft Exchange Server10/1/202317/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaAlta (7.8)0.60%—Microsoft Exchange Server10/1/202317/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaAlta (8)1.6%—Microsoft Exchange Server10/1/202317/6/2026
Microsoft Exchange Server Spoofing Vulnerability
ModificadaAlta (7.5)1.6%—Microsoft Exchange Server10/1/202317/6/2026
Microsoft Exchange Server Information Disclosure Vulnerability
ModificadaAlta (8)1.5%—Microsoft Exchange Server10/1/202317/6/2026
Microsoft Exchange Server Spoofing Vulnerability
ModificadaAlta (8.8)12%—Sage XRT Business Exchange1/1/202317/6/2026
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History.
ModificadaMedia (5.4)0.40%—Sage XRT Business Exchange1/1/202317/6/2026
Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context of other users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Filters and Display model features (OnlineBanking >…
ModificadaCrítica (9.8)6.2%💥 PoCWpswings Return Refund AND Exchange FOR Woocommerce26/12/202217/6/2026
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
ModificadaAlta (7.5)2.5%—Diffie-hellman KEY Exchange Project Diffie-hellman KEY Exchange14/11/202217/6/2026
The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 1996 van Oorschot and Wiener paper found that "(appropriately) short exponents" can be used when there are adequate subgroup constraints, and these short exponents can…
ModificadaAlta (7.8)0.61%—Microsoft Exchange Server9/11/202210/8/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)77%⚠ Explotación activa💥 PoCMicrosoft Exchange Server9/11/202210/8/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaAlta (8)0.83%—Microsoft Exchange Server9/11/202210/8/2026
Microsoft Exchange Server Spoofing Vulnerability
ModificadaAlta (8)0.83%—Microsoft Exchange Server9/11/202210/8/2026
Microsoft Exchange Server Spoofing Vulnerability
ModificadaMedia (5.5)0.15%—Mcafee Data Exchange Layer7/11/202217/6/2026
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.
ModificadaAlta (7.8)0.40%—Autodesk Advanced Material ExchangeAutodesk Moldflow AdviserAutodesk Moldflow CommunicatorAutodesk Moldflow Synergy3/10/202217/6/2026
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
AnalizadaAlta (8)100%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server3/10/202217/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server3/10/202217/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaAlta (8.8)0.35%—Unisys Data Exchange Management Studio13/9/202217/6/2026
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur.
ModificadaMedia (5.5)0.48%—Sound Exchange Project Sound Exchange25/8/202217/6/2026
A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.
ModificadaMedia (5.5)0.45%—Sound Exchange Project Sound Exchange25/8/202217/6/2026
A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.
ModificadaMedia (5.5)0.45%—Sound Exchange Project Sound Exchange25/8/202217/6/2026
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.
ModificadaMedia (5.5)0.48%—Sound Exchange Project Sound Exchange25/8/202217/6/2026
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.
Orbitaley — Vulnerabilidades