Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.31% | — | Haschek PictshareAI | 1/10/2026 | 2/10/2026 | PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform… | |
| Aplazada | Alta (8.8) | 0.37% | — | Haschek PictshareAI | 1/10/2026 | 2/10/2026 | PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file… | |
| Aplazada | Media (6.1) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 1/10/2026 | 1/10/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.7) | 0.33% | — | Barco Clickshare Cx-20 Gen2AI | 28/9/2026 | 28/9/2026 | A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be… | |
| Aplazada | Alta (8.8) | 0.58% | — | Wpcloudplugins USE Your DriveAIWpcloudplugins OUT OF THE BOXAIWpcloudplugins Share ONE DriveAIWpcloudplugins Lets BOXAI | 18/9/2026 | 21/9/2026 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users… | |
| Aplazada | Alta (7.2) | 0.41% | — | Shaneisrael FireshareAI | 15/9/2026 | 30/9/2026 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Shaneisrael FireshareAI | 15/9/2026 | 30/9/2026 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue. | |
| Analizada | Baja (3.5) | 0.58% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.51% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.99% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.40% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.7) | 0.84% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (4.8) | 0.40% | — | Microsoft Sharepoint Server | 8/9/2026 | 10/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Sharepoint Server | 8/9/2026 | 10/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Crítica (9.3) | 0.62% | — | Essential-moos PshareAI | 3/9/2026 | 14/9/2026 | MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or… | |
| Analizada | Media (5.3) | 0.34% | — | Entity Share Websub Project Entity Share Websub | 2/9/2026 | 9/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. |