Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.18% | — | Premmerce User RolesAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Stored XSS.This issue affects Premmerce User Roles: from n/a through <= 1.0.13. | |
| Aplazada | Baja (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 27/10/2025 | 17/6/2026 | A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 27/10/2025 | 17/6/2026 | A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument category_id can lead to cross site… | |
| Aplazada | Media (5.9) | 0.18% | — | Sarah Giles Dynamic User DirectoryAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Stored XSS.This issue affects Dynamic User Directory: from n/a through <= 2.3. | |
| Aplazada | Media (5.9) | 0.22% | — | Webnique Usercentrics CMPAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webnique USERCENTRICS CMP usercentrics-consent-management-platform allows Stored XSS.This issue affects USERCENTRICS CMP: from n/a through <= 1.0.9. | |
| Aplazada | Media (4.3) | 0.25% | — | Premmerce User RolesAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.13. | |
| Analizada | Baja (2.1) | 0.29% | — | Ajayrandhawa User-management-php-mysql | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in ajayrandhawa User-Management-PHP-MYSQL web up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This vulnerability affects unknown code. Performing manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and… | |
| Analizada | Baja (2) | 0.57% | — | Ajayrandhawa User-management-php-mysql | 27/10/2025 | 17/6/2026 | A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part of the file /admin/edit-user.php of the component User Management Interface. Such manipulation of the argument image leads to unrestricted upload. It is possible to… | |
| Aplazada | Media (5.3) | 0.26% | — | User FeedbackAI | 25/10/2025 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including, 1.8.0. This makes it possible for… | |
| Aplazada | Media (6.2) | 0.13% | — | Realtek Ndis Usermode IO DriverAI | 24/10/2025 | 5/7/2026 | An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service. | |
| Aplazada | Media (4.3) | 0.20% | — | Rustaurius Front END UsersAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users.This issue affects Front End Users: from n/a through <= 3.2.33. | |
| Aplazada | Alta (8.8) | 0.36% | — | Nmedia Simple User RegistrationAI | 22/10/2025 | 5/10/2026 | Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Registration: from n/a through <= 6.8. | |
| Aplazada | Media (5.3) | 0.15% | — | Restrict User RegistrationAI | 3/10/2025 | 30/9/2026 | The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the update() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Analizada | Media (4.8) | 0.26% | — | Phpgurukul User Registration & Login AND User Management System | 30/9/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters. | |
| Aplazada | Media (5.9) | 0.22% | — | Cartpauj User NotesAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj User Notes user-notes allows Stored XSS.This issue affects User Notes: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpfront User Role EditorAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor wpfront-user-role-editor allows Stored XSS.This issue affects WPFront User Role Editor: from n/a through <= 4.2.3. | |
| Aplazada | Media (5.5) | 0.33% | — | Mufen Mker Php-usermmAI | 25/9/2025 | 17/6/2026 | A vulnerability was detected in MuFen-mker PHP-Usermm up to 37f2d24e51b04346dfc565b93fc2fc6b37bdaea9. This affects an unknown part of the file /chkuser.php. Performing manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This… | |
| Aplazada | Media (6.5) | 0.21% | — | Renventura WP Delete User AccountsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows Stored XSS.This issue affects WP Delete User Accounts: from n/a through <= 1.2.4. | |
| Aplazada | Media (5.4) | 0.23% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (5.4) | 0.27% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (6.5) | 0.20% | — | Rustaurius Front END UsersAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users front-end-only-users allows Stored XSS.This issue affects Front End Users: from n/a through <= 3.2.35. | |
| Aplazada | Media (6.5) | 0.31% | — | 100plugins Open User MAPAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 100plugins Open User Map open-user-map allows DOM-Based XSS.This issue affects Open User Map: from n/a through <= 1.4.14. | |
| Analizada | Media (5.5) | 0.48% | — | Phpgurukul User Management System | 17/9/2025 | 25/9/2026 | A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument emailid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. | |
| Aplazada | Media (4.3) | 0.20% | — | User Sync Remote User SyncAI | 17/9/2025 | 25/9/2026 | The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the mo_user_sync_form_handler() function. This makes it possible for unauthenticated attackers to deactivate the plugin… | |
| Aplazada | Alta (7.2) | 0.18% | — | Paloaltonetworks User-id Credential AgentAI | 12/9/2025 | 17/6/2026 | — |