Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaAlta (8.8)3.9%—Metagauss Profilegrid3/9/201917/6/2026
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.
ModificadaMedia (6.1)0.92%—Profilepress Loginwp22/8/201917/6/2026
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
ModificadaAlta (7.5)1.3%—Cozmoslabs Profile Builder22/8/201917/6/2026
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
ModificadaMedia (6.1)0.91%—Cozmoslabs Profile Builder21/8/201917/6/2026
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.91%—Cozmoslabs Profile Builder21/8/201917/6/2026
The profile-builder plugin before 2.2.5 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—Cozmoslabs Profile Builder21/8/201917/6/2026
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
ModificadaCrítica (9.8)2.1%—WP Front END Profile Project WP Front END Profile21/8/201917/6/2026
The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.
ModificadaMedia (6.1)0.91%—WP Front END Profile Project WP Front END Profile21/8/201917/6/2026
The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.
ModificadaAlta (8.8)0.67%—Profilepress Loginwp16/8/201917/6/2026
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
ModificadaMedia (6.1)1.1%—Vegadesign Profiledesign CMS13/5/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter.
ModificadaMedia (4.8)0.66%—Profiles Project Profiles26/4/201917/6/2026
XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel.
ModificadaCrítica (9.8)2.1%—IBM Bigfix Webui Profile ManagementIBM Bigfix Webui Software Distribution15/4/201917/6/2026
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886.
ModificadaAlta (7.8)0.43%—Liquidware FlexappLiquidware Profileunity21/2/201917/6/2026
An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell.
ModificadaMedia (6.1)1.1%—Oracle Peoplesoft Enterprise Human Capital Management Eprofile Manager Desktop16/1/201917/6/2026
Vulnerability in the PeopleSoft Enterprise HCM eProfile Manager Desktop component of Oracle PeopleSoft Products (subcomponent: Guided Self Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…
ModificadaAlta (8.8)1.3%—SAP People Profile11/9/201817/6/2026
Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
ModificadaAlta (7.5)2.6%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
ModificadaMedia (4.3)1.6%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (5.4)1.6%💥 ExploitLatest Posts ON Profile Project Latest Posts ON Profile11/5/201817/6/2026
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.
ModificadaMedia (4.8)0.62%—Ultimatemember User Profile & Membership23/4/201817/6/2026
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.
ModificadaAlta (8.8)0.67%—Ultimatemember User Profile & Membership23/4/201817/6/2026
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
ModificadaMedia (5.4)0.51%—Student Profile Management System Script Project Student Profile Management System Script12/4/201817/6/2026
PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php.
Orbitaley — Vulnerabilidades