Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.50%—IBM Aspera Shares7/3/202517/6/2026
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaAlta (7.8)0.24%—Wondershare Filmora4/3/202517/6/2026
Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.
ModificadaMedia (4.3)0.22%—Victorfreitas Wpupper Share Buttons21/2/202517/6/2026
The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to missing or incorrect nonce validation on the 'save_custom_css_request' function. This makes it possible for unauthenticated attackers to inject custom CSS to modify a…
ModificadaMedia (5.4)0.42%—Phpjabbers Shared Asset Booking System20/2/202517/6/2026
PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.
ModificadaMedia (6.5)0.43%—Phpjabbers Shared Asset Booking System20/2/202517/6/2026
PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
ModificadaMedia (6.5)0.40%—Phpjabbers Shared Asset Booking System20/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
AplazadaAlta (7.1)0.15%—Complete SEO Page Post Specific Social Share ButtonsAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specific-social-share-buttons allows Stored XSS.This issue affects Page/Post Specific Social Share Buttons: from n/a through <= 2.1.
AnalizadaAlta (8)34%—Microsoft Sharepoint Server11/2/202517/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaMedia (5.3)0.28%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
AnalizadaMedia (5.4)0.22%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.4)0.21%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AnalizadaMedia (5.4)0.21%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AnalizadaMedia (6.1)0.27%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaMedia (4.8)0.22%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (6.5)0.38%—IBM Aspera Shares5/2/202517/6/2026
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
AplazadaAlta (7.2)0.39%—Anambis Shared FilesAI31/1/202517/6/2026
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.8)0.16%—Wondershare Dr.foneAI30/1/202517/6/2026
Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.exe’ with a malicious binary. This binary will be executed by SYSTEM automatically.
AnalizadaMedia (4.8)0.30%—Artlosk Social Share Buttons28/1/202517/6/2026
The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (6.5)0.49%—Artlosk Share Buttons27/1/202517/6/2026
The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded
AplazadaMedia (6.4)0.34%—Firecask Like AND Share ButtonAI21/1/202517/6/2026
The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaMedia (6.4)0.34%—Videowhisper Video Share VODAI18/1/202517/6/2026
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in all versions up to, and including, 2.6.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AnalizadaMedia (6.3)1.1%—Microsoft Sharepoint Server14/1/202517/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
AnalizadaAlta (7.2)1.8%—Microsoft Sharepoint Server14/1/202517/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.8)0.84%—Microsoft Sharepoint Server14/1/202517/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AplazadaCrítica (9.8)0.59%—Pingvin ShareAI8/1/202517/6/2026
Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issue has been patched…
Orbitaley — Vulnerabilidades