Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.57% | — | Phpgurukul User Registration & Login AND User Management System | 26/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Social LoginAI | 23/11/2024 | 17/6/2026 | The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… | |
| Aplazada | Alta (7.1) | 0.20% | — | A.ankit Webriti Custom Login PageAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in a.ankit Webriti Custom Login webriti-custom-login-page allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through <= 0.3. | |
| Modificada | Media (6.1) | 0.16% | — | Sureshkumar Wp-login Customizer | 18/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sureshdsk wp-login customizer wp-login-customizer allows Stored XSS.This issue affects wp-login customizer: from n/a through <= 1.0. | |
| Aplazada | Alta (7.2) | 0.51% | — | Login Using Wordpress Users WP AS Saml IDPAI | 16/11/2024 | 17/6/2026 | The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (4.8) | 0.47% | — | Phpgurukul User Registration & Login AND User Management System | 14/11/2024 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary scripts via the searchkey parameter in a POST HTTP request. | |
| Analizada | Media (5.3) | 0.60% | — | Phpgurukul User Registration & Login AND User Management System | 14/11/2024 | 17/6/2026 | A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive files and directories via /loginsystem/assets. | |
| Aplazada | Media (6.1) | 0.46% | — | Ajax Login AND Registration Modal Popup Inline FormAI | 13/11/2024 | 17/6/2026 | The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.24. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.1) | 0.27% | — | Sanjay Prasad LoginplusAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanjay Prasad Loginplus loginplus allows Stored XSS.This issue affects Loginplus: from n/a through <= 1.2. | |
| Analizada | Alta (8.1) | 0.52% | — | Heateor Social Login | 6/11/2024 | 17/6/2026 | The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user… | |
| Analizada | Alta (8.1) | 0.54% | — | Wpwebelite Woocommerce Social Login | 5/11/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Analizada | Alta (8.1) | 0.69% | — | Loginizer | 5/11/2024 | 17/6/2026 | The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing… | |
| Analizada | Alta (8.8) | 0.45% | — | Geekcodelab Login AS Users | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a through 1.4.3. | |
| Modificada | Alta (8.8) | 0.93% | 💥 PoC | Priyabratasarkar Token Login | 28/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3. | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Swoopnow 1-click Login\ | 28/10/2024 | 17/6/2026 | Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Wpmet WP Social Login AND Register Social CounterAI | 26/10/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any… | |
| Aplazada | Media (6.4) | 0.33% | — | WP Awesome LoginAI | 26/10/2024 | 17/6/2026 | The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Anand23 Ajax Rating With Custom LoginAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anand23 Ajax Rating with Custom Login ajax-rating-with-custom-login allows SQL Injection.This issue affects Ajax Rating with Custom Login: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 16/10/2024 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Analizada | Crítica (9.8) | 0.60% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter. | |
| Analizada | Alta (7.6) | 0.42% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.58% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request. | |
| Analizada | Media (5.5) | 0.18% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. | |
| Aplazada | Media (4.7) | 0.33% | — | Wp.insider Simple Membership After Login RedirectionAI | 10/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a through <= 1.6. |