Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Ontraport Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function. | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Membership Simplified Project Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges. | |
| Modificada | Media (6.5) | 8.3% | 💥 Exploit | Wpmembership | 3/6/2015 | 17/6/2026 | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php. | |
| Modificada | Media (5) | 18% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 28/11/2014 | 17/6/2026 | Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ocean12tech Membership Manager PRO | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Ocean12tech Membership Manager PRO | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter). | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ezonelink Multiple Membership Script | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Activewebsoftwares Active Membership | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.3% | — | Ocean12 Technologies Membership Manager PRO | 18/11/2008 | 16/6/2026 | Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Develop IT Easy Membership System | 13/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_login.php and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Agtc Websolutions Php-agtc Membership System | 31/10/2007 | 16/6/2026 | adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Interactive-scripts.com PHP Membership Manager | 30/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter. | |
| Modificada | Media (4.9) | 1.1% | — | Agtc Websolutions Php-agtc Membership System | 31/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter). | |
| Modificada | Media (5) | 1.3% | — | Manas Tungare Site Membership Script | 12/3/2006 | 16/6/2026 | SQL injection vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Manas Tungare Site Membership Script | 12/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to inject arbitrary web script or HTML via the Error parameter in (1) login.asp and (2) default.asp. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Pehepe Membership Management System | 7/3/2006 | 16/6/2026 | PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to include and execute arbitrary PHP code via a URL in the uye_klasor parameter, along with a misafir[] parameter that is set to UYE_SEVIYE. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Pehepe Membership Management SystemPehepe Uyelik Sistemi | 7/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable). | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Ocean12 Technologies Membership Manager PRO | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Ocean12 Technologies Membership Manager PRO | 6/4/2005 | 16/6/2026 | SQL injection vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to execute arbitrary SQL commands via the UserID parameter. |