Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.53% | — | Clerk NextjsAIClerk NuxtAIClerk AstroAIClerk SharedAI | 24/4/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7,… | |
| Analizada | Media (5.4) | 0.15% | 💥 PoC | Oracle Peoplesoft Enterprise HCM Shared Components | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… | |
| Analizada | Media (6.5) | 43% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/4/2026 | 17/6/2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 19% | — | Microsoft Sharepoint Server | 14/4/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.26% | — | Illid Share This ImageAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12. | |
| Aplazada | Alta (7.5) | 0.16% | — | Analytify Simple Social Media Share ButtonsAI | 7/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0. | |
| Analizada | Media (6.1) | 0.25% | 💥 PoC | Interzen Zenshare Suite | 2/4/2026 | 24/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter. | |
| Analizada | Crítica (9.1) | 0.72% | — | Shaneisrael Fireshare | 2/4/2026 | 24/7/2026 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not applied to the unauthenticated /api/uploadChunked/public endpoint in the same file (app/server/fireshare/api.py). An unauthenticated… | |
| Analizada | Alta (8.8) | 3.4% | — | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | |
| Analizada | Crítica (9.8) | 3.2% | 💥 Exploit | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. | |
| Analizada | Media (6.1) | 0.24% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.5) | 0.20% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM Aspera Shares | 1/4/2026 | 7/10/2026 | IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | |
| Analizada | Alta (8.1) | 0.54% | — | Shaneisrael Fireshare | 26/3/2026 | 17/6/2026 | Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload directory. The `checkSum` multipart field is used directly in filesystem path… | |
| Aplazada | Media (6.8) | 0.43% | — | Shared FilesAI | 26/3/2026 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector | |
| Aplazada | Media (6.4) | 0.19% | — | EDS Social ShareAI | 21/3/2026 | 17/6/2026 | The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.9) | 0.17% | — | Vivo Easyshare | 13/3/2026 | 17/6/2026 | The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage | |
| Analizada | Alta (8.8) | 2.5% | 💥 PoC | Microsoft Sharepoint Server | 10/3/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server | 10/3/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Sharepoint Server | 10/3/2026 | 17/6/2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.3) | 1.2% | — | Microsoft Sharepoint Server | 10/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.27% | — | Anssi Laitila Shared FilesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.19. |