Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

1357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.31%—Haschek PictshareAI1/10/20262/10/2026
PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform…
AplazadaAlta (8.8)0.37%—Haschek PictshareAI1/10/20262/10/2026
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file…
AplazadaMedia (6.1)0.29%—Social Media Share Buttons Social Sharing IconsAI1/10/20261/10/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (5.7)0.33%—Barco Clickshare Cx-20 Gen2AI28/9/202628/9/2026
A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be…
AplazadaAlta (8.8)0.58%—Wpcloudplugins USE Your DriveAIWpcloudplugins OUT OF THE BOXAIWpcloudplugins Share ONE DriveAIWpcloudplugins Lets BOXAI18/9/202621/9/2026
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users…
AplazadaAlta (7.2)0.41%—Shaneisrael FireshareAI15/9/202630/9/2026
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an…
AplazadaCrítica (9.8)0.63%—Shaneisrael FireshareAI15/9/202630/9/2026
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.
AnalizadaBaja (3.5)0.58%—Microsoft Sharepoint Server8/9/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.51%—Microsoft Sharepoint Server8/9/20269/9/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.99%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.40%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.7)0.84%—Microsoft Sharepoint Server8/9/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (4.8)0.40%—Microsoft Sharepoint Server8/9/202610/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Sharepoint Server8/9/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Sharepoint Server8/9/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Sharepoint Server8/9/202610/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Pendiente de análisisCrítica (9.3)0.62%—Essential-moos PshareAI3/9/202614/9/2026
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or…
AnalizadaMedia (5.3)0.34%—Entity Share Websub Project Entity Share Websub2/9/20269/9/2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.