Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.46% | — | Syracom Secure Login | 10/10/2024 | 17/6/2026 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid. | |
| Modificada | Media (5.4) | 0.34% | — | Syracom Secure Login | 10/10/2024 | 17/6/2026 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted. | |
| Aplazada | Media (5.3) | 0.34% | — | Limit Login Attempts Spam ProtectionAI | 8/10/2024 | 17/6/2026 | The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the… | |
| Analizada | Media (5.4) | 0.31% | — | Prontotools Login Logout Shortcode | 4/10/2024 | 17/6/2026 | The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wechat Social LoginAI | 1/10/2024 | 17/6/2026 | The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Crítica (9.8) | 1.7% | 💥 PoC | Wechat Social LoginAI | 1/10/2024 | 17/6/2026 | The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… | |
| Analizada | Media (6.1) | 0.43% | — | Objectiv Simple Ldap Login | 28/9/2024 | 17/6/2026 | The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Media (5.3) | 0.22% | — | Devfelixmoira Limit Login Attempts Plus | 19/9/2024 | 17/6/2026 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header… | |
| Aplazada | Alta (8.8) | 0.44% | — | Favethemes Houzez Login RegisterAI | 17/9/2024 | 17/6/2026 | Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5. | |
| Analizada | Alta (8.8) | 0.48% | — | Idehweb Login With Phone Number | 14/9/2024 | 17/6/2026 | The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.1) | 0.49% | — | Yithemes Yith Custom Login | 13/9/2024 | 17/6/2026 | The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Media (6.5) | 0.20% | — | Kimhuebel Blogintroduction-wordpress-plugin | 12/9/2024 | 17/6/2026 | The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Onelogin Ruby-samlOmniauth SamlGitlab | 10/9/2024 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with… | |
| Analizada | Alta (8.8) | 3.0% | 💥 Exploit | Codection Clean Login | 30/8/2024 | 17/6/2026 | The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Geekcodelab Login AS UsersAI | 19/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Login AND Registration Attempts LimitAI | 17/8/2024 | 17/6/2026 | The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For… | |
| Aplazada | Media (4.3) | 0.20% | — | Thememylogin Theme MY LoginAI | 16/8/2024 | 17/6/2026 | The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to missing or incorrect nonce validation on the tml_admin_save_ms_settings() function. This makes it possible for unauthenticated attackers to update the theme's settings via a… | |
| Analizada | Crítica (9.8) | 0.61% | — | Wpwebelite Woocommerce Social Login | 12/8/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any… | |
| Modificada | Media (4.8) | 0.26% | — | Idehweb Login With Phone Number | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.35. | |
| Modificada | Media (5.4) | 0.27% | — | Amplifyplugins Login Logo Editor | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AMP-MODE Login Logo Editor allows Stored XSS.This issue affects Login Logo Editor: from n/a through 1.3.3. | |
| Analizada | Alta (7.3) | 0.36% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for… | |
| Analizada | Crítica (9.8) | 0.52% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator… | |
| Analizada | Alta (7.3) | 0.40% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an… | |
| Modificada | Media (6.1) | 0.90% | 💥 Exploit | Wpserveur WPS Hide Login | 15/7/2024 | 17/6/2026 | The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page. | |
| Aplazada | Media (5.3) | 0.42% | — | Trustedlogin VendorAI | 10/7/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1. |