Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.1% | — | Microsoft Exchange Server | 14/2/2023 | 19/8/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 59% | ⚠ Explotación activa | Microsoft Exchange Server | 14/2/2023 | 19/8/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 3.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 17/1/2023 | 17/6/2026 | Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. | |
| Modificada | Alta (7.8) | 0.57% | — | Microsoft Exchange Server | 10/1/2023 | 17/6/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Exchange Server | 10/1/2023 | 17/6/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (8) | 1.6% | — | Microsoft Exchange Server | 10/1/2023 | 17/6/2026 | Microsoft Exchange Server Spoofing Vulnerability | |
| Modificada | Alta (7.5) | 1.6% | — | Microsoft Exchange Server | 10/1/2023 | 17/6/2026 | Microsoft Exchange Server Information Disclosure Vulnerability | |
| Modificada | Alta (8) | 1.5% | — | Microsoft Exchange Server | 10/1/2023 | 17/6/2026 | Microsoft Exchange Server Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 12% | — | Sage XRT Business Exchange | 1/1/2023 | 17/6/2026 | Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History. | |
| Modificada | Media (5.4) | 0.40% | — | Sage XRT Business Exchange | 1/1/2023 | 17/6/2026 | Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context of other users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Filters and Display model features (OnlineBanking >… | |
| Modificada | Crítica (9.8) | 6.2% | 💥 PoC | Wpswings Return Refund AND Exchange FOR Woocommerce | 26/12/2022 | 17/6/2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE | |
| Modificada | Alta (7.5) | 2.5% | — | Diffie-hellman KEY Exchange Project Diffie-hellman KEY Exchange | 14/11/2022 | 17/6/2026 | The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 1996 van Oorschot and Wiener paper found that "(appropriately) short exponents" can be used when there are adequate subgroup constraints, and these short exponents can… | |
| Modificada | Alta (7.8) | 0.61% | — | Microsoft Exchange Server | 9/11/2022 | 10/8/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa💥 PoC | Microsoft Exchange Server | 9/11/2022 | 10/8/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (8) | 0.83% | — | Microsoft Exchange Server | 9/11/2022 | 10/8/2026 | Microsoft Exchange Server Spoofing Vulnerability | |
| Modificada | Alta (8) | 0.83% | — | Microsoft Exchange Server | 9/11/2022 | 10/8/2026 | Microsoft Exchange Server Spoofing Vulnerability | |
| Modificada | Media (5.5) | 0.15% | — | Mcafee Data Exchange Layer | 7/11/2022 | 17/6/2026 | Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker. | |
| Modificada | Alta (7.8) | 0.40% | — | Autodesk Advanced Material ExchangeAutodesk Moldflow AdviserAutodesk Moldflow CommunicatorAutodesk Moldflow Synergy | 3/10/2022 | 17/6/2026 | A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Analizada | Alta (8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Exchange Server | 3/10/2022 | 17/6/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Exchange Server | 3/10/2022 | 17/6/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 0.35% | — | Unisys Data Exchange Management Studio | 13/9/2022 | 17/6/2026 | Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur. | |
| Modificada | Media (5.5) | 0.48% | — | Sound Exchange Project Sound Exchange | 25/8/2022 | 17/6/2026 | A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash. | |
| Modificada | Media (5.5) | 0.45% | — | Sound Exchange Project Sound Exchange | 25/8/2022 | 17/6/2026 | A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash. | |
| Modificada | Media (5.5) | 0.45% | — | Sound Exchange Project Sound Exchange | 25/8/2022 | 17/6/2026 | A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash. | |
| Modificada | Media (5.5) | 0.48% | — | Sound Exchange Project Sound Exchange | 25/8/2022 | 17/6/2026 | A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash. |