Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.42% | — | Richteam Rich-web-share-buttonAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2. | |
| Analizada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Sharepoint Manager Plus | 8/11/2024 | 17/6/2026 | Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option. | |
| Analizada | Media (5.9) | 0.39% | — | Google Quick Share | 7/11/2024 | 17/6/2026 | There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in the Downloads… | |
| Analizada | Media (6.1) | 0.40% | — | Maxfoundry Social Share Buttons | 19/10/2024 | 17/6/2026 | The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.19. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.3) | 0.46% | — | Shudong-share Project Shudong-share | 18/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in HFO4 shudong-share up to 2.4.7. This affects an unknown part of the file /includes/create_share.php of the component Share Handler. The manipulation of the argument fkey leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.34% | — | Themeinwp Social Share With Floating BAR | 18/10/2024 | 17/6/2026 | The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.1) | 17% | 💥 Exploit | Heateor Sassy Social Share | 16/10/2024 | 17/6/2026 | The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Media (6.1) | 0.31% | — | Idiom Easy Social Share Buttons | 10/10/2024 | 17/6/2026 | The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (7.8) | 0.65% | — | Microsoft Sharepoint Server | 8/10/2024 | 17/6/2026 | Microsoft SharePoint Elevation of Privilege Vulnerability | |
| Aplazada | Alta (7.1) | 0.32% | — | Illid Share This ImageAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ILLID Share This Image share-this-image allows Reflected XSS.This issue affects Share This Image: from n/a through <= 2.01. | |
| Modificada | Baja (3.3) | 0.67% | — | Wondershare Edraw | 2/10/2024 | 17/6/2026 | A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and… | |
| Modificada | Media (6.9) | 0.29% | — | M-files Hubshare | 2/10/2024 | 17/6/2026 | Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI | |
| Analizada | Alta (8.8) | 1.2% | — | Plasmoapp Rpshare | 27/9/2024 | 17/6/2026 | Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromConnection method in DownloadTask | |
| Analizada | Alta (8.8) | 0.71% | — | Plasmoapp Rpshare | 27/9/2024 | 17/6/2026 | An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen | |
| Analizada | Alta (8.8) | 0.35% | — | Supsystic SliderSupsystic Social Share Buttons | 26/9/2024 | 17/6/2026 | Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9. | |
| Analizada | Media (6.1) | 0.47% | — | Wp-unit Share This Image | 17/9/2024 | 17/6/2026 | The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they… | |
| Analizada | Media (6.5) | 0.23% | — | IBM Aspera Shares | 16/9/2024 | 17/6/2026 | IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (7.5) | 4.5% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Denial of Service Vulnerability | |
| Analizada | Alta (7.2) | 36% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 4.2% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 8.2% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 51% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Media (5.4) | 0.42% | — | Share-this-image Share This Image | 5/9/2024 | 17/6/2026 | The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.38% | — | Share This Image Project Share This Image | 31/8/2024 | 17/6/2026 | The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (5.3) | 0.50% | — | Hfo4 Shudong-share | 30/8/2024 | 17/6/2026 | A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the component File Extension Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be… |