Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
378 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.42% | — | Supsystic Social Share Buttons | 2/6/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress. | |
| Modificada | Media (4.3) | 0.87% | — | Bigbluebutton | 2/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The… | |
| Modificada | Media (5.3) | 1.0% | — | Bigbluebutton | 2/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The… | |
| Modificada | Media (4.3) | 0.84% | — | Bigbluebutton | 2/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a participant in the meeting. Versions 2.3.18 and… | |
| Modificada | Media (4.3) | 1.0% | — | Bigbluebutton | 2/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of internal ids rather than on verification of… | |
| Modificada | Media (6.5) | 1.1% | — | Bigbluebutton | 1/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server.… | |
| Modificada | Alta (7.5) | 1.6% | — | Bigbluebutton | 1/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service for the bbb-html5 service. The… | |
| Modificada | Media (6.1) | 0.80% | — | Callnowbutton Call NOW Button | 16/5/2022 | 17/6/2026 | The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled | |
| Modificada | Media (6.1) | 0.80% | — | Custom Tinymce Shortcode Button Project Custom Tinymce Shortcode Button | 16/5/2022 | 17/6/2026 | The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (4.8) | 0.60% | — | Wp-experts WP Social Buttons | 9/5/2022 | 17/6/2026 | The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.60% | — | THE Buffer Button Project THE Buffer Button | 21/2/2022 | 17/6/2026 | The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 0.89% | — | Bigbluebutton | 19/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. | |
| Modificada | Alta (8.8) | 3.0% | 💥 Exploit | Wow-company Button Generator | 10/1/2022 | 17/6/2026 | The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE. | |
| Modificada | Media (4.8) | 0.60% | — | Buttonizer | 27/12/2021 | 17/6/2026 | The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8) | 0.57% | — | Likebtn Like Button Rating | 13/12/2021 | 17/6/2026 | The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog. | |
| Modificada | Media (6.1) | 1.2% | — | Wpeden Shiny Buttons | 13/12/2021 | 17/6/2026 | The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template… | |
| Modificada | Media (6.1) | 1.0% | — | Emoji Button Project Emoji Button | 26/11/2021 | 17/6/2026 | @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code. | |
| Modificada | Media (4.8) | 0.68% | — | Addtoany Share Buttons | 8/11/2021 | 17/6/2026 | The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.62% | — | Secondlinethemes Podcast Subscribe Buttons | 18/10/2021 | 17/6/2026 | The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS. | |
| Modificada | Media (4.8) | 0.62% | — | Wpbrigade Simple Social Buttons | 11/10/2021 | 17/6/2026 | The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.62% | — | Addtoany Share Buttons | 6/9/2021 | 17/6/2026 | The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.62% | — | Wpbrigade Simple Social Media Share Buttons | 23/8/2021 | 17/6/2026 | The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (4.8) | 0.63% | — | Smooth Scroll Page Up/down Buttons Project Smooth Scroll Page Up/down Buttons | 12/7/2021 | 17/6/2026 | The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog | |
| Modificada | Media (4.8) | 0.65% | — | Smooth Scroll Page Up/down Buttons Project Smooth Scroll Page Up/down Buttons | 1/6/2021 | 17/6/2026 | The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them |