Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.13% | — | BaidushareAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 baidushare-wp allows Stored XSS.This issue affects 百度分享按钮: from n/a through <= 1.0.6. | |
| Aplazada | Alta (8.8) | 0.25% | — | Video Share VODAI | 28/8/2025 | 17/6/2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Crítica (10) | 0.81% | — | AnyshareAI | 27/8/2025 | 17/6/2026 | AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST and fails to sanitize command-like payloads. An attacker can inject shell syntax that is interpreted by the… | |
| Analizada | Media (5.8) | 0.39% | — | Lumasoft Fotoshare Cloud | 27/8/2025 | 17/6/2026 | Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protected photo albums. | |
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the… | |
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (8.4) | 0.16% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the… | |
| Analizada | Alta (8.4) | 0.16% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the… | |
| Analizada | Alta (7.1) | 16% | — | Microsoft Sharepoint Server | 12/8/2025 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.2) | 0.50% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 12/8/2025 | 17/6/2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.4) | 0.55% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 12/8/2025 | 17/6/2026 | Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 19% | — | Microsoft Sharepoint Server | 12/8/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.16% | — | Autodesk Shared Components | 29/7/2025 | 17/6/2026 | A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Media (6.1) | 0.12% | — | Like AND Share MY SiteAI | 22/7/2025 | 17/6/2026 | The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the 'lsms_admin' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts… | |
| Analizada | Media (6.5) | 100% | 💥 Exploit | Microsoft Sharepoint Server | 20/7/2025 | 17/6/2026 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 20/7/2025 | 4/8/2026 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the… | |
| Analizada | Media (6.5) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 8/7/2025 | 4/8/2026 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 8/7/2025 | 17/6/2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |