Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.37%—Sharedfilespro Shared Files26/8/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28.
AnalizadaMedia (4.3)0.25%—SAP Shared Service Framework13/8/202417/6/2026
SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application
AnalizadaMedia (6.5)0.32%—SAP Shared Service Framework13/8/202417/6/2026
SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.
AnalizadaMedia (5.4)0.38%—IBM Aspera Shares12/8/202417/6/2026
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.
ModificadaAlta (8.5)0.35%—M-files Hubshare29/7/202417/6/2026
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
ModificadaAlta (8.5)0.30%—M-files Hubshare29/7/202417/6/2026
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
ModificadaMedia (5.4)0.31%—Inisev Social Media Share Buttons & Social Sharing Icons21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Inisev Social Media & Share Icons allows Stored XSS.This issue affects Social Media & Share Icons: from n/a through 2.9.1.
ModificadaMedia (5.4)0.27%—Perials Simple Social Share21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Perials Simple Social Share allows Stored XSS.This issue affects Simple Social Share: from n/a through 3.0.
AnalizadaMedia (5.4)0.27%—Oracle Peoplesoft Enterprise HCM Shared Components16/7/202417/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components.…
AnalizadaAlta (7.2)51%⚠ Explotación activaMicrosoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Remote Code Execution Vulnerability
ModificadaAlta (7.2)45%—Microsoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.2)53%—Microsoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.5)2.3%—Microsoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability
ModificadaMedia (5.3)0.41%—Wpkube Kiwi Social Share9/7/202417/6/2026
The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.
AplazadaCrítica (9.8)0.68%—Agreejs SharedAI1/7/202417/6/2026
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
ModificadaMedia (5.3)0.47%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
ModificadaMedia (5.3)0.34%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
ModificadaCrítica (9.8)0.61%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
ModificadaMedia (5.4)0.40%—Sharethis Simple Share Buttons Adder18/6/202417/6/2026
The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
AnalizadaMedia (6.1)0.46%—Heateor Sassy Social Share12/6/202417/6/2026
The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.8)1.2%—Microsoft Sharepoint Server11/6/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AplazadaMedia (6.3)0.28%—Idiom Easy Social Share ButtonsAI9/6/202417/6/2026
Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.
AplazadaMedia (5.3)0.33%—Social Share PRO Social Share Icons AND Social Share ButtonsAI9/6/202417/6/2026
Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2.
AplazadaMedia (5.3)0.42%—Artlosk Share ButtonsAI4/6/202417/6/2026
The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages.
AplazadaMedia (6.1)0.25%—Pointsharp Cryptshare ServerAI27/5/202417/6/2026
Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.
Orbitaley — Vulnerabilidades