Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

378 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.33%—Barco Clickshare Button R9861500d01 Firmware17/12/201917/6/2026
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed 'Clickshare_For_Windows.exe' binary on the ClickShare Button (R9861500D01) loads a number of DLL files dynamically without verifying their integrity.
ModificadaMedia (6.6)0.34%—Barco Clickshare Button R9861500d01 Firmware17/12/201917/6/2026
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Button does not verify the integrity of the mutable content on the UBIFS partition before being used.
ModificadaMedia (6.1)0.91%—Crafty Social Buttons Project Crafty Social Buttons22/8/201917/6/2026
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—AD Buttons Project AD Buttons21/8/201917/6/2026
The ad-buttons plugin before 2.3.2 for WordPress has XSS.
ModificadaMedia (6.1)1.7%💥 ExploitBestwebsoft Twitter Button12/8/201917/6/2026
The twitter-plugin plugin before 2.55 for WordPress has XSS.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Social Buttons Pack12/8/201917/6/2026
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.96%—Simplesharebuttons Simple Share Buttons Adder12/8/201917/6/2026
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
ModificadaMedia (5.3)45%💥 ExploitCrudlab WP Like Button5/7/201917/6/2026
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to…
ModificadaAlta (8.8)1.0%—Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+230/8/201817/6/2026
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure…
ModificadaMedia (6.5)0.79%—Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+230/8/201817/6/2026
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices did not authenticate themselves to the cloud in device to cloud communication.…
ModificadaAlta (8.1)0.86%—Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+230/8/201817/6/2026
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The process of registering a device with a cloud account was based on an activation code…
ModificadaAlta (8.1)0.76%—Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+230/8/201817/6/2026
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by…
ModificadaMedia (6.5)0.53%—Multidots ADD Social Share Messenger Buttons Whatsapp AND Viber31/5/201817/6/2026
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php…
ModificadaMedia (5.4)0.97%—Pootlepress Pootle Button23/10/201717/6/2026
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (6.1)1.4%—Maxbuttons Project Maxbuttons22/5/201717/6/2026
Cross-site scripting vulnerability in MaxButtons prior to version 6.19 and MaxButtons Pro prior to version 6.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)3.4%💥 ExploitDesignsandcode Forget About Shortcode Buttons10/10/201617/6/2026
Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1
ModificadaMedia (6.1)1.6%—Cyber-will Social-button Premium8/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.1%—Maxfoundry Maxbuttons16/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the maxbuttons-controller page to wp-admin/admin.php, related to the button creation page.
ModificadaMedia (6.8)2.8%💥 ExploitSharethis Simple Share Buttons Adder3/7/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to…
ModificadaMedia (4.3)2.1%—Shinephp Thank YOU Counter Button9/3/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) thanks_caption, (2) thanks_caption_style, or (3) thanks_style parameter to wp-admin/options.php.
ModificadaMedia (4.3)5.8%💥 ExploitPpfeufer 2-click-social-media-buttons13/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xing-url parameter.
ModificadaMedia (4.3)1.6%—Ppfeufer 2-click-social-media-buttons13/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "processing of the buttons of Xing and Pinterest".
ModificadaMedia (4.3)1.1%—Peter Proell Tweetbutton7/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in the "official twitter tweet button for your page" (tweetbutton) extension before 1.0.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)8.4%💥 ExploitHP Info CenterHP Quick Launch Button13/12/200716/6/2026
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the…
Orbitaley — Vulnerabilidades