Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… | |
| Aplazada | Media (5.3) | 0.44% | — | Mrvinoth ALL Video ShareAI | 28/8/2026 | 28/8/2026 | Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors | |
| Aplazada | Alta (7.5) | 0.32% | — | Sharedfilespro Shared Files PROAI | 28/8/2026 | 28/8/2026 | The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL. | |
| Aplazada | Media (5.3) | 0.22% | — | Shared FilesAIShared Files PROAI | 28/8/2026 | 28/8/2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to… | |
| Aplazada | Media (6.8) | 0.33% | — | Shared FilesAIShared Files PROAI | 28/8/2026 | 28/8/2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory.… | |
| Aplazada | Media (6.4) | 0.23% | — | Shared FilesAI | 24/8/2026 | 24/8/2026 | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Social Media AND Share IconsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |
| Aplazada | Media (4.8) | 0.17% | — | Achorein Expo-share-intentAI | 24/8/2026 | 26/8/2026 | A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach.… | |
| Analizada | Alta (7.2) | 0.94% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5… | |
| Analizada | Alta (8) | 0.83% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. | |
| Analizada | Alta (7.2) | 0.74% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of… | |
| Aplazada | Alta (8.8) | 0.62% | — | Pingvin Share XAI | 12/8/2026 | 9/9/2026 | Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchronous… | |
| Analizada | Alta (8.7) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.3) | 1.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 16/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |