Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

179 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.20%—Paid Member SubscriptionsAI30/9/202630/9/2026
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
AplazadaMedia (5.3)0.21%—Cozmoslabs Paid Membership SubscriptionsAI23/9/202623/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.
AplazadaBaja (3.7)0.15%—Paidmembershipssubscriptions Paid Memberships SubscriptionsAI23/9/202623/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
AplazadaMedia (5.3)0.30%—Paidmembershipsincorporated Paid Memberships SubscriptionsAI17/9/202618/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
AplazadaMedia (4.3)0.17%—Subscriptions FOR WoocommerceAI16/9/202617/9/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.
AplazadaMedia (5.3)0.34%—Subscriptions FOR WoocommerceAI16/9/202617/9/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates.
AnalizadaAlta (8.3)0.32%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalizadaMedia (6.1)0.41%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.92%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.1)0.53%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.55%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.1)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202622/9/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.9)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.1)0.69%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalizadaMedia (6.5)0.84%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.3)0.76%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202630/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202630/9/2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Pendiente de análisisAlta (7.7)0.53%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch…