Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
378 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.7) | 0.69% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji status for other users. Moderators should only be able to set none as the status… | |
| Modificada | Media (4.3) | 0.29% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join the meeting with the remaining registered users from the same… | |
| Modificada | Media (4.3) | 0.38% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim… | |
| Modificada | Media (5.4) | 0.54% | — | Donation Button Project Donation Button | 12/12/2022 | 17/6/2026 | The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (4.3) | 0.49% | — | Donation Button Project Donation Button | 12/12/2022 | 17/6/2026 | The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone… | |
| Modificada | Media (4.8) | 0.49% | — | Wpupper Share Buttons Project Wpupper Share Buttons | 5/12/2022 | 17/6/2026 | The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.50% | — | Spacexchimp Social Media Follow Buttons BAR | 30/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress. | |
| Modificada | Crítica (9.8) | 1.4% | — | Bigbluebutton | 29/9/2022 | 17/6/2026 | BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken. | |
| Modificada | Baja (3.5) | 0.78% | — | Bigbluebutton | 29/9/2022 | 17/6/2026 | In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js. | |
| Modificada | Media (4.8) | 0.51% | — | Maxfoundry Maxbuttons | 23/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress | |
| Analizada | Media (4.8) | 0.62% | — | Cagewebdev Float TO TOP Button | 19/9/2022 | 17/6/2026 | The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.40% | — | Maxfoundry Maxbuttons | 22/8/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress. | |
| Modificada | Media (5.4) | 0.36% | — | Okapitech WP Sticky Button | 22/8/2022 | 17/6/2026 | The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues | |
| Modificada | Alta (8.8) | 0.98% | — | Supsystic Social Share Buttons | 22/7/2022 | 17/6/2026 | Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. | |
| Modificada | Alta (8.8) | 0.92% | — | Supsystic Social Share Buttons | 22/7/2022 | 17/6/2026 | Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. | |
| Modificada | Media (4.8) | 0.52% | — | Social Media Share Buttons Project Social Media Share Buttons | 20/7/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress. | |
| Modificada | Alta (8.8) | 0.62% | — | Button Widget Smartsoft | 18/7/2022 | 17/6/2026 | The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious… | |
| Modificada | Media (6.1) | 0.77% | — | Bigbluebutton | 27/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript), the script gets executed. Additionally… | |
| Modificada | Media (5.4) | 1.3% | — | Bigbluebutton | 27/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has… | |
| Modificada | Media (5.3) | 0.69% | — | Bigbluebutton Greenlight | 27/6/2022 | 17/6/2026 | Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6. | |
| Modificada | Media (4.3) | 0.43% | — | Supsystic Social Share Buttons | 27/6/2022 | 17/6/2026 | The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks. | |
| Modificada | Media (5.4) | 0.45% | — | Bigbluebutton | 24/6/2022 | 17/6/2026 | BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each time the attacker sends a private message to the victim or when… | |
| Modificada | Media (4.8) | 0.59% | — | Wp-experts Custom Share Buttons With Floating Sidebar | 20/6/2022 | 17/6/2026 | The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.5) | 0.80% | — | Likebtn Like Button Rating | 13/6/2022 | 17/6/2026 | The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body | |
| Modificada | Media (5.4) | 0.84% | — | Bigbluebutton Greenlight | 2/6/2022 | 17/6/2026 | BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously. |