Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.35% | — | Dearhive Social Media Share Buttons MasshareAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47. | |
| Aplazada | Media (6.4) | 0.28% | — | Videowhisper Video Share VODAI | 18/12/2024 | 17/6/2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, and including, 2.6.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Crítica (9.3) | 1.8% | 💥 PoC | Richteam Rich-web-share-buttonAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | ECT Social ShareAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in etemplates ECT Social Share ect-social-share allows Stored XSS.This issue affects ECT Social Share: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.35% | — | Social Share PRO Social Share Icons AND Social Share ButtonsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7. | |
| Aplazada | Media (4.3) | 0.47% | — | Inisev Social Media & Share IconsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media & Share Icons: from n/a through 2.8.1. | |
| Analizada | Alta (7.4) | 2.3% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Analizada | Alta (8.2) | 1.6% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Elevation of Privilege Vulnerability | |
| Analizada | Media (5.5) | 1.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/12/2024 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 2.5% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Information Disclosure Vulnerability | |
| Analizada | Media (6.5) | 3.2% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Information Disclosure Vulnerability | |
| Aplazada | Alta (7.6) | 0.45% | — | Barco Clickshare Cx-30AIBarco Clickshare Cx-20AIBarco Clickshare C-5AIBarco Clickshare C-10AI+2 | 10/12/2024 | 17/6/2026 | An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root. | |
| Aplazada | Media (4.3) | 0.41% | — | Sharethis Social Media FeatherAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in socialmediafeather Social Media Feather social-media-feather allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media Feather: from n/a through <= 2.1.3. | |
| Analizada | Media (4.3) | 0.34% | — | Samsung Quick Share | 3/12/2024 | 17/6/2026 | Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location. | |
| Aplazada | Alta (7.1) | 0.17% | — | Acbaltaci Google Plus Share AND Plusone ButtonAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in acbaltaci Google Plus Share and +1 Button google-plus-share-and-plusone-button allows Stored XSS.This issue affects Google Plus Share and +1 Button: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.29% | — | Cosmosfarm-share-buttonsAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 코스모스팜 – Cosmosfarm 소셜 공유 버튼 By 코스모스팜 cosmosfarm-share-buttons allows Stored XSS.This issue affects 소셜 공유 버튼 By 코스모스팜: from n/a through <= 1.9. | |
| Analizada | Media (6.1) | 0.90% | 💥 PoC | Heateor Sassy Social Share | 30/11/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.9) | 0.77% | — | Intlify SharedAI | 29/11/2024 | 17/6/2026 | @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain,… | |
| Aplazada | Media (6.5) | 0.32% | — | Leroysabrina Simple Social Share BlockAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leroysabrina Simple Social Share Block simple-social-share-block allows Stored XSS.This issue affects Simple Social Share Block: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Nomaniplex Easy Social SharebarAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nomaniplex Easy Social Sharebar easy-social-sharebar allows Stored XSS.This issue affects Easy Social Sharebar: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.5) | 0.15% | — | Wondershare PDF ReaderAI | 18/11/2024 | 17/6/2026 | A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Analizada | Alta (8.8) | 0.52% | — | Jenkins Shared Library Version Override | 13/11/2024 | 17/6/2026 | Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without… | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Thunderbolt ShareAI | 13/11/2024 | 17/6/2026 | Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.26% | — | Sharethepractice Christian Science Bible Lesson Subjects | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gabriel Serafini Christian Science Bible Lesson Subjects christian-science-bible-lesson-subjects allows DOM-Based XSS.This issue affects Christian Science Bible Lesson Subjects: from n/a through <= 2.0. | |
| Aplazada | Alta (8.5) | 0.42% | — | Richteam Rich-web-share-buttonAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2. |