Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.18% | — | Share TO Google ClassroomAI | 11/11/2025 | 7/10/2026 | The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.8) | 0.20% | — | Autodesk Shared Components | 7/11/2025 | 7/10/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.1) | 0.18% | — | Idiom Easy Social Share ButtonsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-share-buttons3 allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through < 10.7.1. | |
| Analizada | Media (5.3) | 0.33% | — | Codeshare | 4/11/2025 | 17/6/2026 | codeshare v1.0.0 was discovered to contain an information leakage vulnerability. | |
| Aplazada | Alta (7.1) | 0.45% | — | Axewater SharewarezAI | 23/10/2025 | 17/6/2026 | A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME. | |
| Aplazada | Media (5.9) | 0.22% | — | Nikitas Georgopoulos Weshare ButtonsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NIKITAS GEORGOPOULOS WeShare Buttons e-mailit allows Stored XSS.This issue affects WeShare Buttons: from n/a through <= 13.0.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Themeinity SharebangAI | 22/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeinity ShareBang, Ultimate Social Share Buttons for WordPress sharebang allows Reflected XSS.This issue affects ShareBang, Ultimate Social Share Buttons for WordPress: from n/a through <= 1.4. | |
| Analizada | Alta (8.8) | 2.5% | — | Microsoft Sharepoint Server | 14/10/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.66% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+3 | 14/10/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.1) | 0.48% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+3 | 14/10/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 1.4% | — | Microsoft Sharepoint Server | 14/10/2025 | 17/6/2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.39% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.4) | 0.19% | — | ALL Social Share OptionsAI | 30/9/2025 | 17/6/2026 | The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.8) | 0.18% | — | Autodesk Shared Components | 22/9/2025 | 17/6/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Media (6.5) | 0.20% | — | Ronald Huereca Highlight AND ShareAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Stored XSS.This issue affects Highlight and Share: from n/a through <= 5.1.1. | |
| Analizada | Crítica (9.4) | 3.0% | — | Wondershare Repairit | 17/9/2025 | 25/9/2026 | Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissions granted to an… | |
| Analizada | Crítica (9.1) | 2.8% | — | Wondershare Repairit | 17/9/2025 | 25/9/2026 | Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissions… | |
| Modificada | Alta (7) | 0.26% | — | M-files Hubshare | 15/9/2025 | 17/6/2026 | Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users. | |
| Analizada | Alta (7.8) | 0.71% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server | 9/9/2025 | 17/6/2026 | Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 9/9/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 20% | 💥 PoC | Microsoft Sharepoint Server | 9/9/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (6.4) | 0.24% | — | Html Social Share ButtonsAI | 6/9/2025 | 17/6/2026 | The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_btn' shortcode in all versions up to, and including, 2.1.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpkube Kiwi Social ShareAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-social-share allows Stored XSS.This issue affects Kiwi: from n/a through <= 2.1.8. | |
| Analizada | Media (6.5) | 0.26% | — | Shaneisrael Fireshare | 2/9/2025 | 17/6/2026 | FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET /api/videos/public?sort= This parameter is unsafely evaluated in a SQL ORDER BY clause without proper sanitization, allowing an attacker to inject arbitrary SQL subqueries. |