Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.32%—WP User ProfilesAI6/10/20266/10/2026
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
AplazadaMedia (4.9)0.23%—Fivestarplugins Five Star Business Profile AND SchemaAI4/10/20266/10/2026
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and…
AplazadaMedia (6.1)0.22%—ProfilepressAI3/10/20266/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input…
AplazadaAlta (8.8)0.63%—ProfilepressAI3/10/20266/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated…
AplazadaMedia (5.3)0.20%—Metagauss ProfilegridAI1/10/20261/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.
AplazadaMedia (6.5)0.21%—Cozmoslabs Profile BuilderAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
AplazadaAlta (7.2)0.26%—User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.20%—Codeselling User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.8)0.44%💥 PoCMetabox Meta BOX AIOAIMetabox Meta BOX Frontend SubmissionAIMetabox Meta BOX User ProfileAI22/9/202622/9/2026
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET…
AplazadaAlta (8.1)0.65%—ProfilepressAI19/9/202621/9/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not…
Pendiente de análisisMedia (6.2)0.18%—Opentelemetry Ebpf ProfilerAI11/9/202625/9/2026
OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FIFO, and block indefinitely, preventing…
AplazadaAlta (7.2)0.42%—Codesigner User Profile BuilderAI7/9/20269/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (6.1)0.38%—Codesmiths User Profile BuilderAI1/9/20261/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.33%—Codesigner User Profile BuilderAI1/9/20261/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaCrítica (9.2)0.92%—Profilepress WP User AvatarAI31/8/20268/9/2026
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a…
AplazadaMedia (5.5)0.50%—Cozmoslabs Profile BuilderAI31/8/202631/8/2026
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is…
AplazadaAlta (8.2)0.32%—Codesmiths User Profile BuilderAI29/8/202631/8/2026
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other…
AplazadaMedia (6.6)0.42%💥 PoCCozmoslabs User Profile BuilderAI29/8/202631/8/2026
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is…
AplazadaMedia (6.8)0.43%—User Profile BuilderAI29/8/202631/8/2026
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by…
AplazadaMedia (6.5)0.31%—ProfilepressAI21/8/202626/8/2026
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date.
AplazadaMedia (5.4)0.52%—ProfilepressAI16/8/202620/8/2026
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not…
AplazadaCrítica (9.8)3.9%💥 ExploitUser Profile BuilderAI15/8/202620/8/2026
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is…
AplazadaMedia (6.5)0.22%—Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
AnalizadaAlta (8.8)1.0%—Microsoft Application Insights Profiler7/8/202617/8/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (5.3)0.29%—Cozmoslabs Profile BuilderAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Orbitaley — Vulnerabilidades