Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.49%—Leechesnutt Slick Social Share Buttons11/1/202417/6/2026
The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update…
ModificadaAlta (8.8)31%—Microsoft Sharepoint Server9/1/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.5)0.46%—Bestwebsoft Like & Share26/12/202317/6/2026
The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag
ModificadaMedia (4.8)0.39%—Getsocial Social Share Buttons & Analytics15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Getsocial, S.A. Social Share Buttons & Analytics Plugin – GetSocial.Io allows Stored XSS.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.Io: from n/a through 4.3.12.
ModificadaMedia (4.8)0.39%—Codebard Fast Custom Social Share30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1.
ModificadaAlta (8.8)0.26%—Dangngocbinh Easy Call NOW BY Thikshare22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaMedia (5.4)0.43%—Shareaholic15/11/202317/6/2026
The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in versions up to, and including, 9.7.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and…
ModificadaMedia (6.8)3.4%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server14/11/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)0.30%—Wbcomdesigns Buddypress Activity Social Share12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions.
ModificadaAlta (8.8)0.31%—Superbthemes Superb Social Media Share Buttons AND Follow Buttons10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions.
ModificadaMedia (5.5)0.19%—Samsung Quick Share7/11/202317/6/2026
Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.
ModificadaMedia (6.5)0.36%—Elastic Sharepoint Online Python Connector26/10/202317/6/2026
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through…
ModificadaAlta (8.8)0.22%—Ultimatelysocial Social Media Share Buttons & Social Sharing Icons20/10/202317/6/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated…
ModificadaMedia (6.5)1.2%💥 PoCUltimatelysocial Social Media Share Buttons & Social Sharing Icons20/10/202317/6/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well…
ModificadaCrítica (9.8)1.1%—Hynotech Dropbox Folder Share20/10/202317/6/2026
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to…
ModificadaMedia (5.4)0.34%—Firecask Whatsapp Share Button20/10/202317/6/2026
The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (6.1)0.42%—Tammersoft Shared Files16/10/202317/6/2026
The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.
ModificadaAlta (8.8)0.25%—Sumo Social Share Boost6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sumo Social Share Boost plugin <= 4.5 versions.
ModificadaMedia (4.8)0.39%—Walkswithme Social Share ON Image Hover2/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jobin Jose WWM Social Share On Image Hover plugin <= 2.2 versions.
ModificadaMedia (6.1)0.41%—Ultimatelysocial Social Media Share Buttons & Social Sharing Icons27/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions.
ModificadaAlta (7.2)0.45%—Hynotech Dropbox Folder Share16/9/202317/6/2026
The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify…
ModificadaAlta (8.8)2.1%—Microsoft Sharepoint Server12/9/202317/6/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
ModificadaAlta (7.3)0.84%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+112/9/202317/6/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaMedia (4.8)0.37%—Sumo Social Share Boost1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.