Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.67% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 8/7/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 1.2% | — | Microsoft Sharepoint Server | 8/7/2025 | 17/6/2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.6) | 3.0% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server | 8/7/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.44% | — | Fabiantodt Private Post Share | 4/7/2025 | 17/6/2026 | The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API. | |
| Analizada | Alta (8.8) | 0.86% | — | Gameusers Game Users Share Button | 28/6/2025 | 17/6/2026 | The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in all versions up to, and including, 1.3.0. This makes it possible for Subscriber-level attackers to add arbitrary file paths (such as… | |
| Analizada | Baja (2.1) | 0.34% | — | Astuntechnology Ishare Maps | 15/6/2025 | 17/6/2026 | A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the file atCheckJS.aspx. The manipulation of the argument ref leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Alta (7.3) | 0.17% | — | Clipshare ServerAI | 11/6/2025 | 17/6/2026 | ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and loads system libraries like CRYPTBASE.dll and WindowsCodecs.dll from its own directory before the system path. A local, non-privileged user who can write… | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 10/6/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.65% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 10/6/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.64% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 10/6/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 21% | 💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 10/6/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 20% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 10/6/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.24% | — | Heateor Sassy Social Share | 7/6/2025 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.2) | 0.36% | — | Shared FilesAI | 3/6/2025 | 17/6/2026 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible… | |
| Analizada | Media (5.3) | 0.36% | — | Astuntechnology Ishare Maps | 31/5/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.aspx. The manipulation of the argument atTxtStreet leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.36% | — | Astuntechnology Ishare Maps | 31/5/2025 | 17/6/2026 | A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file historic1.asp. The manipulation of the argument Zoom leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to… | |
| Aplazada | Media (6.4) | 0.30% | — | Minimal Share ButtonsAI | 30/5/2025 | 17/6/2026 | The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Alta (7.3) | 0.30% | — | Wondershare Filmora | 26/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to uncontrolled search path. Attacking locally is a requirement.… | |
| Analizada | Media (6.9) | 0.54% | — | Yangshare Warehouse Management System | 26/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Analizada | Alta (8) | 0.26% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.69% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | |
| Analizada | Crítica (9.1) | 0.30% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization. | |
| Aplazada | Media (4.3) | 0.23% | — | Sharespine Woocommerce ConnectorAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharespine Woocommerce Connector: from n/a through <= 4.7.55. | |
| Analizada | Media (4.8) | 0.32% | — | Missionmike Simple Share | 15/5/2025 | 17/6/2026 | The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Reputeinfosystems Social Share AND Social Locker | 15/5/2025 | 17/6/2026 | The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |