Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)0.50%—Microsoft Exchange ServerAI2/10/20263/10/2026
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
En análisisMedia (6)0.30%—Rabbitmq JMS Topic ExchangeAI25/9/202629/9/2026
RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rjms_erlang_selector binding expression whose LIKE evaluator expanded percent and underscore wildcards into overlapping…
En análisisMedia (6)0.29%—RabbitmqAIRabbitmq JMS Topic ExchangeAI23/9/202624/9/2026
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0, When a binding is created on an x-jms-topic exchange, add_binding/3 reads the rjms_erlang_selector argument and passes it through erl_scan:string/1 then erl_parse:parse_term/1. erl_scan:string/1 interns every atom…
En análisisMedia (6)0.26%—RabbitmqAIRabbitmq Consistent Hash ExchangeAI23/9/202624/9/2026
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3 parses the routing key as an integer weight N and computes ring positions with lists:seq(NextN0, NextN0 + N - 1). validate_binding/2 only checks N >= 1 , no upper bound. The resulting list is stored…
AplazadaAlta (7.5)0.35%—Wpswings Return Refund AND Exchange FOR WoocommerceAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Pendiente de análisisAlta (8.1)0.72%—Microsoft Exchange ServerAI8/9/20269/9/2026
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.1)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202622/9/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.9)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.1)0.69%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalizadaMedia (6.5)0.84%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.3)0.76%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202630/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202630/9/2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AplazadaMedia (6.5)0.27%—Wpswings Return Refund AND Exchange FOR WoocommerceAI26/8/202626/8/2026
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return…
AnalizadaCrítica (10)0.90%—Microsoft Exchange Online20/8/202624/8/2026
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisBaja (3.3)0.17%—Onnx Open Neural Network ExchangeAI18/8/202618/9/2026
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer…
AnalizadaAlta (8.8)0.94%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202617/8/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202614/8/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202614/8/2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)2.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
ModificadaAlta (8)0.69%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/20262/9/2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition11/8/202614/8/2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Exchange Online24/7/202629/7/2026
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.