Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.66% | — | Dongsheng Logistics SoftwareAI | 27/8/2025 | 4/8/2026 | Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted multipart/form-data POST request. This allows remote… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Online Course Registration | 21/8/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (6.5) | 0.21% | — | Mirror-registryAI | 20/8/2025 | 17/6/2026 | The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns. | |
| Aplazada | Media (6.4) | 0.24% | — | WP Tournament RegistrationAI | 6/8/2025 | 17/6/2026 | The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Modificada | Alta (7.1) | 0.33% | — | Phpgurukul Online Course Registration | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack. | |
| Analizada | Baja (2.1) | 0.44% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Login and User Management System 3.3. It has been declared as critical. This vulnerability affects unknown code of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3. It has been classified as critical. This affects an unknown part of the file /admin/lastthirtyays-reg-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.41% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/lastsevendays-reg-users.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The… | |
| Aplazada | Media (6.4) | 0.32% | — | Wpeverest User RegistrationAI | 22/7/2025 | 17/6/2026 | The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.4) | 0.33% | 💥 PoC | Akbim Software Online Exam RegistrationAI | 21/7/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers. This issue affects Online Exam Registration: before 14.03.2025. | |
| Analizada | Baja (2.1) | 0.42% | — | Phpgurukul User Registration & Login AND User Management System | 13/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.5) | 0.52% | — | Phpgurukul User Registration & Login AND User Management System | 13/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The… | |
| Aplazada | Media (6.5) | 0.30% | — | Aviplugins WP Register Profile With ShortcodeAI | 11/7/2025 | 17/6/2026 | The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'rp_user_data' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data from user meta… | |
| Aplazada | Crítica (10) | 2.0% | 💥 Exploit | Docusaurus Plugin Content GistsAI | 9/7/2025 | 17/6/2026 | The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration options. The token,… | |
| Aplazada | Crítica (10) | 16% | 💥 Exploit | Genetechsolutions PIE RegisterAI | 9/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can… | |
| Aplazada | Crítica (10) | 0.40% | — | Liquidthemes LogisticshubAI | 4/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a Web Shell to a Web Server.This issue affects LogisticsHub: from n/a through <= 1.1.6. | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Analizada | Media (6.1) | 0.24% | — | Hellomohsinkhan WP Front-end Login AND Register | 2/7/2025 | 17/6/2026 | The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (8.1) | 0.44% | — | Julialang Registrator | 25/6/2025 | 17/6/2026 | Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities) a shell script injection can occur within the `withpasswd` function.… | |
| Analizada | Alta (8.1) | 0.68% | — | Julialang Registrator | 25/6/2025 | 17/6/2026 | Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettreesha()` function.… | |
| Aplazada | Media (6.5) | 0.23% | — | Aviplugins WP Register Profile With ShortcodeAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com WP Register Profile With Shortcode wp-register-profile-with-shortcode allows Stored XSS.This issue affects WP Register Profile With Shortcode: from n/a through <= 3.6.3. | |
| Analizada | Media (6.1) | 0.31% | — | Sick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic AnalyticsSick Media Server+2 | 12/6/2025 | 17/6/2026 | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks). | |
| Analizada | Media (6.5) | 0.37% | — | Avaya Media ServerSick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. | |
| Analizada | Alta (7.5) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product. | |
| Analizada | Media (5.1) | 0.23% | — | Webkul Bagisto | 9/6/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can be exploited to steal sensitive user… |