Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.49% | — | Leechesnutt Slick Social Share Buttons | 11/1/2024 | 17/6/2026 | The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update… | |
| Modificada | Alta (8.8) | 31% | — | Microsoft Sharepoint Server | 9/1/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 0.46% | — | Bestwebsoft Like & Share | 26/12/2023 | 17/6/2026 | The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag | |
| Modificada | Media (4.8) | 0.39% | — | Getsocial Social Share Buttons & Analytics | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Getsocial, S.A. Social Share Buttons & Analytics Plugin – GetSocial.Io allows Stored XSS.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.Io: from n/a through 4.3.12. | |
| Modificada | Media (4.8) | 0.39% | — | Codebard Fast Custom Social Share | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1. | |
| Modificada | Alta (8.8) | 0.26% | — | Dangngocbinh Easy Call NOW BY Thikshare | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (5.4) | 0.43% | — | Shareaholic | 15/11/2023 | 17/6/2026 | The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in versions up to, and including, 9.7.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (6.8) | 3.4% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 14/11/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 0.30% | — | Wbcomdesigns Buddypress Activity Social Share | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Superbthemes Superb Social Media Share Buttons AND Follow Buttons | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Quick Share | 7/11/2023 | 17/6/2026 | Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files. | |
| Modificada | Media (6.5) | 0.36% | — | Elastic Sharepoint Online Python Connector | 26/10/2023 | 17/6/2026 | An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through… | |
| Modificada | Alta (8.8) | 0.22% | — | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 20/10/2023 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated… | |
| Modificada | Media (6.5) | 1.2% | 💥 PoC | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 20/10/2023 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well… | |
| Modificada | Crítica (9.8) | 1.1% | — | Hynotech Dropbox Folder Share | 20/10/2023 | 17/6/2026 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to… | |
| Modificada | Media (5.4) | 0.34% | — | Firecask Whatsapp Share Button | 20/10/2023 | 17/6/2026 | The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.42% | — | Tammersoft Shared Files | 16/10/2023 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts. | |
| Modificada | Alta (8.8) | 0.25% | — | Sumo Social Share Boost | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sumo Social Share Boost plugin <= 4.5 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Walkswithme Social Share ON Image Hover | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jobin Jose WWM Social Share On Image Hover plugin <= 2.2 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions. | |
| Modificada | Alta (7.2) | 0.45% | — | Hynotech Dropbox Folder Share | 16/9/2023 | 17/6/2026 | The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Modificada | Alta (8.8) | 2.1% | — | Microsoft Sharepoint Server | 12/9/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.3) | 0.84% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/9/2023 | 17/6/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Media (4.8) | 0.37% | — | Sumo Social Share Boost | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. |