Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

1358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.4%—Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+1328/8/202317/6/2026
Zoho ManageEngine Active Directory 360 versiones 4315 e inferiores, ADAudit Plus 7202 e inferiores, ADManager Plus 7200 e inferiores, Asset Explorer 6993 e inferiores y 7xxx 7002 e inferiores, Cloud Security Plus 4161 e inferiores, Data Security Plus 6110 e inferiores, Eventlog Analyzer 12301 y siguientes, Exchange…
ModificadaMedia (4.8)0.37%—Supito Mahato Simple Light Weight Social Share10/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sudipto Pratap Mahato Simple Light Weight Social Share plugin <= 2.0 versions.
ModificadaMedia (6.5)2.1%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability
ModificadaAlta (8)2.0%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (8)2.0%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaMedia (6.5)1.9%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability
ModificadaMedia (4.3)0.61%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+628/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers…
ModificadaMedia (6.5)0.69%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+728/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,…
ModificadaMedia (4.3)0.56%—Vuukle Comments, Reactions, Share Bar, Revenue12/7/202317/6/2026
The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for…
ModificadaAlta (7.5)1.1%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
ModificadaAlta (8.8)4.3%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.3%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (8.8)38%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.6%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitCitrix Sharefile Storage Zones Controller10/7/202317/6/2026
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
ModificadaMedia (6.1)6.0%💥 ExploitHeator Social Share, Social Login AND Social Comments19/6/202317/6/2026
The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (6.5)1.0%—Microsoft Sharepoint Server14/6/202317/6/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
ModificadaMedia (6.3)0.88%—Microsoft Sharepoint Server14/6/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (7.3)1.2%—Microsoft Sharepoint Server14/6/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaMedia (6.5)2.0%—Microsoft Sharepoint Server14/6/202317/6/2026
Microsoft SharePoint Server Denial of Service Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/6/202317/6/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaCrítica (9.8)1.4%—Wpkube Kiwi Social Share7/6/202317/6/2026
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary…
ModificadaAlta (8.8)0.27%—Simplesharebuttons Simple Share Buttons Adder25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions.
ModificadaAlta (7.8)0.83%💥 ExploitWondershare Mobiletrans24/5/20239/7/2026
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.