Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Mohsin Khan WP Front END Login AND RegisterAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Khan WP Front-end login and register wp-front-end-login-and-register allows Reflected XSS.This issue affects WP Front-end login and register: from n/a through <= 2.1.0. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Favethemes Homey Login RegisterAI | 21/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Escalation.This issue affects Homey Login Register: from n/a through <= 2.4.0. | |
| Analizada | Media (5.3) | 0.41% | — | Zotregistry ZOT | 17/1/2025 | 17/6/2026 | zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (meta.db) is an append-list so group revocations/removals are ignored in the API. SetUserGroups is alled on login, but instead of replacing the group memberships, they are appended. This may be due to… | |
| Aplazada | Media (6.4) | 0.34% | — | Vcita Event Registration CalendarAI | 15/1/2025 | 17/6/2026 | The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (8.8) | 0.36% | — | Registration Role Project Registration Role | 9/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1. | |
| Aplazada | Media (6.1) | 0.23% | — | Stop Registration SpamAI | 17/12/2024 | 17/6/2026 | The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick… | |
| Aplazada | Alta (7.1) | 0.14% | — | TOM Royal Stop Registration SpamAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from n/a through 1.23. | |
| Aplazada | Crítica (9.8) | 1.9% | 💥 PoC | Saiful.total Wp-nssuser-registerAI | 16/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.3) | 0.30% | — | Genetech PIE Register PremiumAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3. | |
| Aplazada | Crítica (10) | 0.77% | — | Genetech PIE Register PremiumAI | 9/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3. | |
| Modificada | Alta (7.5) | 0.57% | — | Metagauss Registrationmagic | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 5.2.3.0. | |
| Modificada | Media (5.3) | 0.41% | — | Wpeverest User Registration | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1. | |
| Aplazada | Media (5.3) | 0.76% | — | Miniorange Wordpress Social Login AND RegisterAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Genetech PIE Register PremiumAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Pie Register Premium allows Reflected XSS.This issue affects Pie Register Premium: from n/a before 3.8.3.3. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Nmedia Simple User RegistrationAI | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in N-Media Simple User Registration wp-registration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Simple User Registration: from n/a through <= 5.5. | |
| Aplazada | Alta (8.1) | 0.51% | — | RegistrationformsAI | 4/12/2024 | 17/6/2026 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.9. This is due to insufficient verification on the user… | |
| Analizada | Media (6.9) | 0.65% | — | Phpgurukul User Registration & Login AND User Management System | 27/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.57% | — | Phpgurukul User Registration & Login AND User Management System | 26/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The… | |
| Modificada | Media (4.8) | 0.29% | — | Hyscaler WP Roles AT Registration | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NetTantra WP Roles at Registration allows Stored XSS.This issue affects WP Roles at Registration: from n/a through 0.23. | |
| Analizada | Media (5.4) | 0.45% | — | Cisco Prime Access Registrar | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. The attacker would require valid credentials for the device. This vulnerability is due to… | |
| Analizada | Media (4.8) | 0.47% | — | Phpgurukul User Registration & Login AND User Management System | 14/11/2024 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary scripts via the searchkey parameter in a POST HTTP request. | |
| Analizada | Media (5.3) | 0.60% | — | Phpgurukul User Registration & Login AND User Management System | 14/11/2024 | 17/6/2026 | A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive files and directories via /loginsystem/assets. | |
| Aplazada | Media (6.1) | 0.46% | — | Ajax Login AND Registration Modal Popup Inline FormAI | 13/11/2024 | 17/6/2026 | The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.24. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Baja (2.3) | 0.29% | — | Digistar Ag-30 PlusAI | 12/11/2024 | 17/6/2026 | A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The complexity of an attack is rather high. The exploitability is told to be… | |
| Analizada | Media (4.8) | 0.40% | — | Phpgurukul Online Marriage Registration System | 11/11/2024 | 17/6/2026 | A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter. |