Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.7%—Microsoft Exchange Server9/8/202217/6/2026
Microsoft Exchange Server Information Disclosure Vulnerability
ModificadaMedia (4.3)2.0%—Microsoft Exchange Server9/8/202217/6/2026
Microsoft Exchange Server Information Disclosure Vulnerability
ModificadaAlta (8)2.4%—Microsoft Exchange Server9/8/202217/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaAlta (8)2.2%—Microsoft Exchange Server9/8/202217/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaAlta (8)2.7%—Microsoft Exchange Server9/8/202217/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaMedia (5.7)2.2%—Microsoft Exchange Server9/8/202217/6/2026
Microsoft Exchange Server Information Disclosure Vulnerability
ModificadaMedia (5.4)0.56%—Inoutscripts Blockchain Altexchanger26/7/202217/6/2026
Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.
ModificadaMedia (5.5)1.2%—Sound Exchange Project Sound Exchange25/5/202217/6/2026
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
ModificadaMedia (5.5)1.2%—Sound Exchange Project Sound Exchange25/5/202217/6/2026
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
ModificadaAlta (7.5)1.1%—Inoutscripts Blockchain Altexchanger23/5/202217/6/2026
Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
ModificadaAlta (7.5)1.1%—Inoutscripts Blockchain Altexchanger23/5/202217/6/2026
Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.
ModificadaAlta (7.5)1.2%—Inoutscripts Blockchain AltexchangerInoutscripts Blockchain Fiatexchanger23/5/202217/6/2026
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
ModificadaAlta (8.2)0.87%—Microsoft Exchange Server10/5/202217/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
ModificadaCrítica (9.1)1.6%—Sound Exchange Project Sound Exchange2/5/202217/6/2026
A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.
ModificadaAlta (8.8)7.9%💥 ExploitZohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter Plus18/4/202217/6/2026
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
ModificadaAlta (8.8)2.2%—Sound Exchange Project Sound Exchange14/4/202217/6/2026
A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+241/4/202217/6/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModificadaCrítica (9.8)4.1%—Uni-stuttgart Frams' Fast File Exchange17/3/202217/6/2026
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).
ModificadaMedia (6.5)32%—Microsoft Exchange Server9/3/202217/6/2026
Microsoft Exchange Server Spoofing Vulnerability
ModificadaAlta (8.8)41%💥 ExploitMicrosoft Exchange Server9/3/202217/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaMedia (5.4)0.60%—Translationexchange Translation Exchange21/2/202217/6/2026
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.
ModificadaCrítica (9)1.1%—Microsoft Exchange Server11/1/202217/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaCrítica (9)0.93%—Microsoft Exchange Server11/1/202217/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaCrítica (9)1.1%—Microsoft Exchange Server11/1/202217/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
AnalizadaAlta (8.8)92%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server10/11/202119/8/2026
Microsoft Exchange Server Remote Code Execution Vulnerability