Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.34%—Inisev Social Media Share Buttons & Social Sharing Icons15/5/202517/6/2026
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AnalizadaAlta (7)1.3%—Microsoft Sharepoint Server13/5/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)2.5%—Microsoft Sharepoint Server13/5/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7)1.4%—Microsoft Sharepoint Server13/5/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.61%—Microsoft Sharepoint Server13/5/202517/6/2026
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
AplazadaMedia (6.1)0.31%—ADD Google Plus ONE Social Share ButtonAI25/4/202517/6/2026
The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated attackers to update…
AplazadaMedia (4.7)0.32%—Heateor Sassy Social ShareAI24/4/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Phishing.This issue affects Sassy Social Share: from n/a through <= 3.3.73.
AplazadaMedia (4.3)0.15%—Sharethis Dashboard FOR Google AnalyticsAI10/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ShareThis ShareThis Dashboard for Google Analytics googleanalytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through <= 3.2.3.
AnalizadaAlta (7.8)0.77%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server8/4/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)5.1%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server8/4/202517/6/2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.2)24%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server8/4/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.82%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+28/4/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.86%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+18/4/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.80%—Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+38/4/202517/6/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
AplazadaMedia (4.3)0.43%—Joao Romao Social Share Buttons AND Analytics Plugin Getsocial IOAI4/4/202517/6/2026
Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin – GetSocial.io wp-share-buttons-analytics-by-getsocial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.io: from n/a through <= 4.5.
AplazadaCrítica (9.3)0.38%—Reputeinfosystems Social Share AND Social LockerAI3/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems Social Share And Social Locker social-share-and-social-locker-arsocial allows Blind SQL Injection.This issue affects Social Share And Social Locker: from n/a through <= 1.4.2.
AplazadaAlta (7.1)0.24%—Reputeinfosystems Social Share AND Social LockerAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems Social Share And Social Locker social-share-and-social-locker-arsocial allows Reflected XSS.This issue affects Social Share And Social Locker: from n/a through <= 1.4.1.
AplazadaAlta (7.1)0.14%—WP ProfitshareAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ProfitShare.ro WP Profitshare wp-profitshare allows Stored XSS.This issue affects WP Profitshare: from n/a through <= 1.4.9.
AplazadaMedia (6.5)0.36%—Wpshare247 Elementor AddonsAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons wpshare247-elementor-addons allows Stored XSS.This issue affects WPSHARE247 Elementor Addons: from n/a through <= 2.5.
AplazadaMedia (6.5)0.21%—Mindshare Labs INC WP Ultimate SearchAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mindshare Labs, Inc. WP Ultimate Search wp-ultimate-search allows Stored XSS.This issue affects WP Ultimate Search: from n/a through <= 2.0.3.
AplazadaMedia (5.4)0.15%—Nertworks ALL IN ONE Social Share ToolsAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in nertworks NertWorks All in One Social Share Tools nertworks-all-in-one-social-share-tools allows Cross Site Request Forgery.This issue affects NertWorks All in One Social Share Tools: from n/a through <= 1.26.
AplazadaAlta (7.1)0.37%—Videowhisper Video Share VODAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Video Share VOD video-share-vod allows Reflected XSS.This issue affects Video Share VOD: from n/a through <= 2.7.9.
AplazadaAlta (7.6)0.55%—Profitshare.ro WP ProfitshareAI24/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ProfitShare.ro WP Profitshare wp-profitshare allows SQL Injection.This issue affects WP Profitshare: from n/a through <= 1.4.9.
AplazadaAlta (7.1)0.22%—Dvs11 Random Posts MP3 Player SharebuttonAI15/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dvs11 Random Posts, Mp3 Player + ShareButton random-posts-mp3-player-sharebutton allows Reflected XSS.This issue affects Random Posts, Mp3 Player + ShareButton: from n/a through <= 1.4.1.
AnalizadaMedia (5.3)0.28%—Sharethis Dashboard FOR Google Analytics14/3/202517/6/2026
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() function in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to disable all features.
Orbitaley — Vulnerabilidades