Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Paid Member SubscriptionsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Cozmoslabs Paid Membership SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled. | |
| Aplazada | Baja (3.7) | 0.15% | — | Paidmembershipssubscriptions Paid Memberships SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. | |
| Aplazada | Media (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 17/9/2026 | 18/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Aplazada | Media (4.3) | 0.17% | — | Subscriptions FOR WoocommerceAI | 16/9/2026 | 17/9/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making. | |
| Aplazada | Media (5.3) | 0.34% | — | Subscriptions FOR WoocommerceAI | 16/9/2026 | 17/9/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates. | |
| Analizada | Alta (8.3) | 0.32% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.55% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.1) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 22/9/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.9) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.3) | 0.76% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 30/9/2026 | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch… |