Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
1358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versiones 4315 e inferiores, ADAudit Plus 7202 e inferiores, ADManager Plus 7200 e inferiores, Asset Explorer 6993 e inferiores y 7xxx 7002 e inferiores, Cloud Security Plus 4161 e inferiores, Data Security Plus 6110 e inferiores, Eventlog Analyzer 12301 y siguientes, Exchange… | |
| Modificada | Media (4.8) | 0.37% | — | Supito Mahato Simple Light Weight Social Share | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sudipto Pratap Mahato Simple Light Weight Social Share plugin <= 2.0 versions. | |
| Modificada | Media (6.5) | 2.1% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Alta (8) | 2.0% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8) | 2.0% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (6.5) | 1.9% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (4.3) | 0.56% | — | Vuukle Comments, Reactions, Share Bar, Revenue | 12/7/2023 | 17/6/2026 | The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for… | |
| Modificada | Alta (7.5) | 1.1% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.8) | 4.3% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.3% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 38% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 2.6% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Citrix Sharefile Storage Zones Controller | 10/7/2023 | 17/6/2026 | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Heator Social Share, Social Login AND Social Comments | 19/6/2023 | 17/6/2026 | The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (6.5) | 1.0% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Media (6.3) | 0.88% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (7.3) | 1.2% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (6.5) | 2.0% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Denial of Service Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Crítica (9.8) | 1.4% | — | Wpkube Kiwi Social Share | 7/6/2023 | 17/6/2026 | The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary… | |
| Modificada | Alta (8.8) | 0.27% | — | Simplesharebuttons Simple Share Buttons Adder | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions. | |
| Modificada | Alta (7.8) | 0.83% | 💥 Exploit | Wondershare Mobiletrans | 24/5/2023 | 9/7/2026 | Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file. |