Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.42%—Richteam Rich-web-share-buttonAI11/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.
AnalizadaAlta (8.1)2.4%—Zohocorp Manageengine Sharepoint Manager Plus8/11/202417/6/2026
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
AnalizadaMedia (5.9)0.39%—Google Quick Share7/11/202417/6/2026
There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in the Downloads…
AnalizadaMedia (6.1)0.40%—Maxfoundry Social Share Buttons19/10/202417/6/2026
The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.19. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaMedia (5.3)0.46%—Shudong-share Project Shudong-share18/10/202417/6/2026
A vulnerability classified as critical has been found in HFO4 shudong-share up to 2.4.7. This affects an unknown part of the file /includes/create_share.php of the component Share Handler. The manipulation of the argument fkey leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (6.1)0.34%—Themeinwp Social Share With Floating BAR18/10/202417/6/2026
The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaMedia (6.1)17%💥 ExploitHeateor Sassy Social Share16/10/202417/6/2026
The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AnalizadaMedia (6.1)0.31%—Idiom Easy Social Share Buttons10/10/202417/6/2026
The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaAlta (7.8)0.65%—Microsoft Sharepoint Server8/10/202417/6/2026
Microsoft SharePoint Elevation of Privilege Vulnerability
AplazadaAlta (7.1)0.32%—Illid Share This ImageAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ILLID Share This Image share-this-image allows Reflected XSS.This issue affects Share This Image: from n/a through <= 2.01.
ModificadaBaja (3.3)0.67%—Wondershare Edraw2/10/202417/6/2026
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and…
ModificadaMedia (6.9)0.29%—M-files Hubshare2/10/202417/6/2026
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
AnalizadaAlta (8.8)1.2%—Plasmoapp Rpshare27/9/202417/6/2026
Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromConnection method in DownloadTask
AnalizadaAlta (8.8)0.71%—Plasmoapp Rpshare27/9/202417/6/2026
An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen
AnalizadaAlta (8.8)0.35%—Supsystic SliderSupsystic Social Share Buttons26/9/202417/6/2026
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9.
AnalizadaMedia (6.1)0.47%—Wp-unit Share This Image17/9/202417/6/2026
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they…
AnalizadaMedia (6.5)0.23%—IBM Aspera Shares16/9/202417/6/2026
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
AnalizadaAlta (7.5)4.5%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Denial of Service Vulnerability
AnalizadaAlta (7.2)36%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.2)4.2%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.2)8.2%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (8.8)51%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaMedia (5.4)0.42%—Share-this-image Share This Image5/9/202417/6/2026
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.4)0.38%—Share This Image Project Share This Image31/8/202417/6/2026
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaMedia (5.3)0.50%—Hfo4 Shudong-share30/8/202417/6/2026
A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the component File Extension Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be…
Orbitaley — Vulnerabilidades