Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.50% | — | IBM Aspera Shares | 7/3/2025 | 17/6/2026 | IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Modificada | Alta (7.8) | 0.24% | — | Wondershare Filmora | 4/3/2025 | 17/6/2026 | Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation. | |
| Modificada | Media (4.3) | 0.22% | — | Victorfreitas Wpupper Share Buttons | 21/2/2025 | 17/6/2026 | The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to missing or incorrect nonce validation on the 'save_custom_css_request' function. This makes it possible for unauthenticated attackers to inject custom CSS to modify a… | |
| Modificada | Media (5.4) | 0.42% | — | Phpjabbers Shared Asset Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters. | |
| Modificada | Media (6.5) | 0.43% | — | Phpjabbers Shared Asset Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (6.5) | 0.40% | — | Phpjabbers Shared Asset Booking System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Aplazada | Alta (7.1) | 0.15% | — | Complete SEO Page Post Specific Social Share ButtonsAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specific-social-share-buttons allows Stored XSS.This issue affects Page/Post Specific Social Share Buttons: from n/a through <= 2.1. | |
| Analizada | Alta (8) | 34% | — | Microsoft Sharepoint Server | 11/2/2025 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Media (5.3) | 0.28% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers. | |
| Analizada | Media (5.4) | 0.22% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (6.1) | 0.27% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (4.8) | 0.22% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.5) | 0.38% | — | IBM Aspera Shares | 5/2/2025 | 17/6/2026 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. | |
| Aplazada | Alta (7.2) | 0.39% | — | Anambis Shared FilesAI | 31/1/2025 | 17/6/2026 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.8) | 0.16% | — | Wondershare Dr.foneAI | 30/1/2025 | 17/6/2026 | Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.exe’ with a malicious binary. This binary will be executed by SYSTEM automatically. | |
| Analizada | Media (4.8) | 0.30% | — | Artlosk Social Share Buttons | 28/1/2025 | 17/6/2026 | The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.5) | 0.49% | — | Artlosk Share Buttons | 27/1/2025 | 17/6/2026 | The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded | |
| Aplazada | Media (6.4) | 0.34% | — | Firecask Like AND Share ButtonAI | 21/1/2025 | 17/6/2026 | The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.34% | — | Videowhisper Video Share VODAI | 18/1/2025 | 17/6/2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in all versions up to, and including, 2.6.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Media (6.3) | 1.1% | — | Microsoft Sharepoint Server | 14/1/2025 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Analizada | Alta (7.2) | 1.8% | — | Microsoft Sharepoint Server | 14/1/2025 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.84% | — | Microsoft Sharepoint Server | 14/1/2025 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Aplazada | Crítica (9.8) | 0.59% | — | Pingvin ShareAI | 8/1/2025 | 17/6/2026 | Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issue has been patched… |