Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.37% | — | Sharedfilespro Shared Files | 26/8/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28. | |
| Analizada | Media (4.3) | 0.25% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application | |
| Analizada | Media (6.5) | 0.32% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application. | |
| Analizada | Media (5.4) | 0.38% | — | IBM Aspera Shares | 12/8/2024 | 17/6/2026 | IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574. | |
| Modificada | Alta (8.5) | 0.35% | — | M-files Hubshare | 29/7/2024 | 17/6/2026 | Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session | |
| Modificada | Alta (8.5) | 0.30% | — | M-files Hubshare | 29/7/2024 | 17/6/2026 | Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session | |
| Modificada | Media (5.4) | 0.31% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Inisev Social Media & Share Icons allows Stored XSS.This issue affects Social Media & Share Icons: from n/a through 2.9.1. | |
| Modificada | Media (5.4) | 0.27% | — | Perials Simple Social Share | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Perials Simple Social Share allows Stored XSS.This issue affects Simple Social Share: from n/a through 3.0. | |
| Analizada | Media (5.4) | 0.27% | — | Oracle Peoplesoft Enterprise HCM Shared Components | 16/7/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components.… | |
| Analizada | Alta (7.2) | 51% | ⚠ Explotación activa | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 45% | — | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 53% | — | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 2.3% | — | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Media (5.3) | 0.41% | — | Wpkube Kiwi Social Share | 9/7/2024 | 17/6/2026 | The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Agreejs SharedAI | 1/7/2024 | 17/6/2026 | agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Modificada | Media (5.3) | 0.47% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter. | |
| Modificada | Media (5.3) | 0.34% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive. | |
| Modificada | Crítica (9.8) | 0.61% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter. | |
| Modificada | Media (5.4) | 0.40% | — | Sharethis Simple Share Buttons Adder | 18/6/2024 | 17/6/2026 | The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (6.1) | 0.46% | — | Heateor Sassy Social Share | 12/6/2024 | 17/6/2026 | The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft Sharepoint Server | 11/6/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Aplazada | Media (6.3) | 0.28% | — | Idiom Easy Social Share ButtonsAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Aplazada | Media (5.3) | 0.33% | — | Social Share PRO Social Share Icons AND Social Share ButtonsAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2. | |
| Aplazada | Media (5.3) | 0.42% | — | Artlosk Share ButtonsAI | 4/6/2024 | 17/6/2026 | The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages. | |
| Aplazada | Media (6.1) | 0.25% | — | Pointsharp Cryptshare ServerAI | 27/5/2024 | 17/6/2026 | Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages. |