Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.57% | — | PSW Front END Login RegistrationAI | 31/5/2025 | 17/6/2026 | The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forget() function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 0.64% | — | Miniorange Wordpress Social Login AND RegisterAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.6.10. | |
| Aplazada | Crítica (9.8) | 25% | 💥 Exploit | Gilblas Ngunte Possi PSW Front-end Login AND RegistrationAI | 23/5/2025 | 17/6/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13. | |
| Aplazada | Media (5.5) | 0.17% | — | KeycloakAIZotregistry ZOTAI | 22/5/2025 | 17/6/2026 | zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example… | |
| Aplazada | Alta (8.6) | 0.35% | — | Typo3AIStanislas Rolland SR Feuser RegisterAI | 21/5/2025 | 17/6/2026 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference. | |
| Aplazada | Crítica (10) | 0.71% | — | Stanislas Rolland SR Feuser RegisterAI | 21/5/2025 | 17/6/2026 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution. | |
| Aplazada | Alta (7.1) | 0.22% | — | Elbisnero Wordpress Events Calendar Registration AND TicketsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0. | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul User Registration & Login AND User Management System | 19/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. This vulnerability affects unknown code of the file /edit-profile.php. The manipulation of the argument Contact leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Online Marriage Registration System | 19/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Marriage Registration System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/between-dates-application-report.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul Online Course Registration | 16/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /news.php. The manipulation of the argument newstitle leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.72% | — | Phpgurukul Online Course Registration | 16/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been classified as critical. Affected is an unknown function of the file /edit-student-profile.php. The manipulation of the argument cgpa leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Online Course Registration | 16/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul Online Course Registration | 16/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/department.php. The manipulation of the argument department leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Online Course Registration | 16/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/course.php. The manipulation of the argument coursecode leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (4.8) | 0.31% | — | Metagauss Registrationmagic | 15/5/2025 | 17/6/2026 | The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (8.2) | 0.23% | — | Redhat Mirror Registry FOR OpenshiftAIRedhat QuayAI | 9/5/2025 | 17/6/2026 | A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod. | |
| Aplazada | Crítica (9.8) | 7.4% | 💥 Exploit | Frontend Login AND Registration BlocksAI | 9/5/2025 | 17/6/2026 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the… | |
| Aplazada | Media (5.3) | 0.42% | — | User Registration MembershipAI | 6/5/2025 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key.… | |
| Analizada | Media (5.4) | 0.22% | — | Alphaefficiencyteam Custom Login AND Registration | 5/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and Registration: from n/a through 1.0.0. | |
| Modificada | Crítica (9.8) | 0.52% | — | Phpgurukul User Registration & Login AND User Management System | 28/4/2025 | 5/7/2026 | A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account… | |
| Aplazada | Media (5.4) | 0.27% | — | Alphaefficiencyteam Custom Login AND RegistrationAI | 25/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0. | |
| Aplazada | Media (5.9) | 0.27% | — | Ralf Hortt Confirm User RegistrationAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ralf Hortt Confirm User Registration confirm-user-registration allows Stored XSS.This issue affects Confirm User Registration: from n/a through <= 2.1.5. | |
| Modificada | Media (6.1) | 0.29% | — | Wpeverest User Registration & Membership | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through < 4.2.0. | |
| Aplazada | Alta (8.8) | 0.44% | — | Frontend Login AND Registration BlocksAI | 24/4/2025 | 17/6/2026 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Field Logistics Manage LogisticsAI | 22/4/2025 | 17/6/2026 | SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not impacted. |