Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Profilepress Loginwp | 6/12/2021 | 17/6/2026 | The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Vtune Profiler | 17/11/2021 | 17/6/2026 | Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 7.6% | 💥 Exploit | Cozmoslabs Profile Builder | 16/8/2021 | 17/6/2026 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for… | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Properfraction Profilepress | 9/8/2021 | 17/6/2026 | The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as… | |
| Modificada | Media (5.4) | 0.78% | — | Cozmoslabs User Profile Picture | 2/8/2021 | 17/6/2026 | The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles). | |
| Modificada | Media (4.8) | 0.65% | — | Properfraction Profilepress | 2/8/2021 | 17/6/2026 | The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin to set JavaScript payloads in them even… | |
| Modificada | Media (4.8) | 0.61% | — | Cozmoslabs Profile Builder | 2/8/2021 | 17/6/2026 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored… | |
| Modificada | Crítica (9.8) | 6.7% | 💥 Exploit | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Crítica (9.8) | 2.1% | — | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Vtune Profiler | 9/6/2021 | 17/6/2026 | Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.1) | 0.85% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey. | |
| Modificada | Alta (8.8) | 0.85% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device… | |
| Modificada | Alta (7.5) | 0.83% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time). | |
| Modificada | Alta (7.5) | 0.91% | — | Bluetooth Core SpecificationBluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment. | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 7/10/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Cozmoslabs User Profile Picture | 5/4/2021 | 17/6/2026 | The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information. | |
| Modificada | Alta (7.8) | 0.45% | — | Rockwellautomation Drivetools Add-on ProfilesRockwellautomation Drivetools SP | 18/3/2021 | 17/6/2026 | Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Vtune Profiler | 12/11/2020 | 17/6/2026 | Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 8.0% | — | Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+33 | 1/10/2020 | 17/6/2026 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still… | |
| Modificada | Alta (8.8) | 2.2% | — | Seczetta Neprofile | 26/8/2020 | 17/6/2026 | A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can poison this header resulting in an adversary controlling the execution flow for the 302 HTTP status. | |
| Modificada | Alta (8.8) | 3.0% | — | Seczetta Neprofile | 15/7/2020 | 17/6/2026 | A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon uploading a carefully crafted JPEG file as part of the profile avatar. | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Alta (7.8) | 0.34% | — | Intel Vtune Profiler | 17/1/2020 | 17/6/2026 | Improper access control in driver for Intel(R) VTune(TM) Amplifier for Windows* before update 8 may allow an authenticated user to potentially enable escalation of privilege via local access. |