Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (8.8) | 3.9% | — | Metagauss Profilegrid | 3/9/2019 | 17/6/2026 | The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code. | |
| Modificada | Media (6.1) | 0.92% | — | Profilepress Loginwp | 22/8/2019 | 17/6/2026 | The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs. | |
| Modificada | Alta (7.5) | 1.3% | — | Cozmoslabs Profile Builder | 22/8/2019 | 17/6/2026 | The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. | |
| Modificada | Media (6.1) | 0.91% | — | Cozmoslabs Profile Builder | 21/8/2019 | 17/6/2026 | The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.91% | — | Cozmoslabs Profile Builder | 21/8/2019 | 17/6/2026 | The profile-builder plugin before 2.2.5 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Cozmoslabs Profile Builder | 21/8/2019 | 17/6/2026 | The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. | |
| Modificada | Crítica (9.8) | 2.1% | — | WP Front END Profile Project WP Front END Profile | 21/8/2019 | 17/6/2026 | The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue. | |
| Modificada | Media (6.1) | 0.91% | — | WP Front END Profile Project WP Front END Profile | 21/8/2019 | 17/6/2026 | The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 0.67% | — | Profilepress Loginwp | 16/8/2019 | 17/6/2026 | The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 1.1% | — | Vegadesign Profiledesign CMS | 13/5/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter. | |
| Modificada | Media (4.8) | 0.66% | — | Profiles Project Profiles | 26/4/2019 | 17/6/2026 | XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel. | |
| Modificada | Crítica (9.8) | 2.1% | — | IBM Bigfix Webui Profile ManagementIBM Bigfix Webui Software Distribution | 15/4/2019 | 17/6/2026 | IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886. | |
| Modificada | Alta (7.8) | 0.43% | — | Liquidware FlexappLiquidware Profileunity | 21/2/2019 | 17/6/2026 | An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell. | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Peoplesoft Enterprise Human Capital Management Eprofile Manager Desktop | 16/1/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM eProfile Manager Desktop component of Oracle PeopleSoft Products (subcomponent: Guided Self Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Alta (8.8) | 1.3% | — | SAP People Profile | 11/9/2018 | 17/6/2026 | Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (5.4) | 1.6% | 💥 Exploit | Latest Posts ON Profile Project Latest Posts ON Profile | 11/5/2018 | 17/6/2026 | The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field. | |
| Modificada | Media (4.8) | 0.62% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | |
| Modificada | Alta (8.8) | 0.67% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin. | |
| Modificada | Media (5.4) | 0.51% | — | Student Profile Management System Script Project Student Profile Management System Script | 12/4/2018 | 17/6/2026 | PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php. |