Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.31% | — | M-files Hubshare | 24/5/2024 | 17/6/2026 | Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser | |
| Modificada | Media (5.4) | 0.26% | — | Sharethis Share Buttons | 23/5/2024 | 17/6/2026 | The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethis-inline-button' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.27% | — | WP Font Awesome Share IconsAI | 22/5/2024 | 17/6/2026 | The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpfai_social' shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.17% | — | Codebard Fast Custom Social Share | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard fast-custom-social-share-by-codebard.This issue affects Fast Custom Social Share by CodeBard: from n/a through <= 1.1.2. | |
| Aplazada | Alta (8.5) | 0.57% | — | Idiom Easy Social Share ButtonsAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Analizada | Alta (7.2) | 84% | — | Microsoft Sharepoint Server | 14/5/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 56% | 💥 PoC | Microsoft Sharepoint Server | 14/5/2024 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Aplazada | Media (4.7) | 0.38% | — | Illid Share This ImageAI | 2/5/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share This Image: from n/a through 1.97. | |
| Analizada | Media (4.7) | 0.48% | — | Heateor Sassy Social Share | 26/4/2024 | 17/6/2026 | The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (5.3) | 0.39% | — | Anssi Laitila Shared FilesAI | 23/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16. | |
| Analizada | Media (5.9) | 0.40% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 17/4/2024 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Analizada | Baja (3.1) | 1.4% | — | Microsoft Sharepoint Server | 9/4/2024 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Analizada | Alta (7.8) | 0.30% | 💥 PoC | Wondershare Filmora | 8/4/2024 | 17/6/2026 | Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe | |
| Aplazada | Alta (7.1) | 0.18% | — | Toastie Studio Woocommerce Social Media Share ButtonsAI | 2/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a through 1.3.0. | |
| Aplazada | Alta (7.1) | 0.35% | — | Idiom Easy Social Share ButtonsAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appscreo Easy Social Share Buttons allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Analizada | Alta (8.1) | 5.0% | — | Microsoft Azure C Shared Utility | 26/3/2024 | 17/6/2026 | The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in… | |
| Aplazada | Media (5.4) | 0.46% | — | Sharethis Dashboard FOR Google AnalyticsAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4. | |
| Modificada | Alta (8.8) | 0.67% | — | Sygnoos Social Media Share Buttons | 20/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0. | |
| Modificada | Alta (8.8) | 0.77% | — | Sygnoos Social Media Share Buttons | 16/3/2024 | 17/6/2026 | The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP… | |
| Analizada | Alta (7.8) | 3.9% | — | Microsoft Sharepoint Server | 12/3/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (5.4) | 0.51% | — | Heateor Sassy Social Share | 6/3/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping on user supplied attributes such as 'url'. This makes… | |
| Modificada | Media (6.4) | 0.47% | — | Heateor Sassy Social Share | 29/2/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.56 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.49% | — | Simplesharebuttons Simple Share Buttons Adder | 29/2/2024 | 17/6/2026 | The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Modificada | Media (5.5) | 0.36% | — | Nsasoft Sharealarmpro | 22/1/2024 | 17/6/2026 | A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. Local access is required to approach this attack. The exploit has… | |
| Modificada | Crítica (9.8) | 0.39% | — | Studionetworksolutions Sharebrowser | 17/1/2024 | 17/6/2026 | Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636. |