Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.28% | — | Simple-membership-plugin Simple Membership | 24/1/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1. | |
| Modificada | Crítica (9.8) | 1.00% | — | Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+11 | 19/1/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long… | |
| Modificada | Media (6.1) | 0.38% | — | Simple-membership-plugin Simple Membership | 11/1/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (5.3) | 0.51% | — | Strangerstudios Paid Memberships PRO | 11/1/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up… | |
| Modificada | Media (6.5) | 0.44% | — | Butlerblog Wp-members | 4/1/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails,… | |
| Modificada | Media (5.4) | 0.61% | — | Carmelogarcia Intern Membership Management System | 28/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /user_registration/ of the component User Registration. The manipulation of the argument userName/firstName/lastName/userEmail with the input… | |
| Modificada | Crítica (9.8) | 0.72% | — | Carmelogarcia Intern Membership Management System | 28/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Intern Membership Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user_registration/ of the component User Registration. The manipulation of the argument userName leads to sql injection. The exploit has been… | |
| Modificada | Media (6.1) | 0.46% | — | Simple-membership-plugin Simple Membership | 19/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8. | |
| Modificada | Alta (8.8) | 51% | — | Strangerstudios Paid Memberships PRO | 18/11/2023 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or… | |
| Modificada | Media (4.8) | 0.39% | — | Dazzlersoft Team Members Showcase | 16/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 versions. | |
| Modificada | Alta (7.5) | 0.69% | — | Memberscard Project Memberscard | 14/11/2023 | 17/6/2026 | An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | |
| Modificada | Alta (8.2) | 0.58% | — | Linecorp Fukunaga Memberscard | 25/10/2023 | 17/6/2026 | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | |
| Modificada | Media (4.3) | 0.39% | — | Strangerstudios Paid Memberships PRO | 20/10/2023 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they… | |
| Modificada | Crítica (9.8) | 0.82% | — | Razormist Simple Membership System | 29/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.45% | — | Kokoroe Members Card Project Kokoroe Members Card | 20/9/2023 | 17/6/2026 | An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Media (6.5) | 0.46% | — | THE B Members Card Project THE B Members Card | 18/9/2023 | 9/7/2026 | An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Alta (7.5) | 0.61% | — | Razormist Simple Membership System | 17/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.61% | — | Razormist Simple Membership System | 9/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been rated as critical. This issue affects some unknown processing of the file delete_member.php. The manipulation of the argument mem_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Razormist Simple Membership System | 9/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.60% | — | Razormist Simple Membership System | 8/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been classified as critical. This affects an unknown part of the file club_edit_query.php. The manipulation of the argument club_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.1) | 0.57% | — | Simple-membership-plugin Simple Membership | 6/9/2023 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could inject arbitrary web scripts into pages… | |
| Modificada | Media (4.8) | 0.36% | — | Minorange Wordpress Yourmembership Single Sign-on | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Login plugin <= 1.1.3 versions. | |
| Modificada | Media (4.3) | 0.34% | — | Samsung Members | 10/8/2023 | 17/6/2026 | Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information. | |
| Modificada | Media (4.3) | 0.50% | — | Butlerblog Wp-members | 12/7/2023 | 17/6/2026 | The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on… | |
| Modificada | Media (4.8) | 0.37% | — | Ntzapps CRM Memberships | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <= 1.6 versions. |