Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.53%—Simple-membership-plugin Simple Membership21/3/202217/6/2026
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
ModificadaMedia (4.7)0.47%—Simple-membership-plugin Simple Membership28/2/202217/6/2026
The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
ModificadaCrítica (9.8)82%💥 ExploitStrangerstudios Paid Memberships PRO7/2/202217/6/2026
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
ModificadaCrítica (9.8)1.3%—Simple Membership System Using PHP AND Ajax Project Simple Membership System Using PHP AND Ajax24/1/202217/6/2026
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.
ModificadaMedia (6.1)1.9%💥 ExploitStrangerstudios Paid Memberships PRO27/12/202117/6/2026
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)1.0%—Profilepress User Registration, Login Form, User Profile & Membership13/12/202117/6/2026
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)1.0%—Profilepress User Registration, Login Form, User Profile & Membership13/12/202117/6/2026
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
ModificadaAlta (8.8)1.7%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions13/9/202117/6/2026
The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.
ModificadaBaja (3.3)0.22%—Samsung Members8/7/202117/6/2026
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.
ModificadaAlta (7.8)1.7%—Samsung Members8/7/202117/6/2026
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.
ModificadaBaja (3.3)0.23%—Samsung Members8/7/202117/6/2026
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.
ModificadaAlta (7.5)3.1%💥 PoCSamsung Members9/4/202117/6/2026
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
ModificadaMedia (5.4)0.66%—Wpdarko Team Members18/3/202117/6/2026
Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.
ModificadaAlta (8.8)2.0%—Strangerstudios Paid Memberships PRO18/3/202117/6/2026
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (3.3)0.22%—Samsung Members4/3/202117/6/2026
Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.
ModificadaBaja (3.3)0.22%—Samsung Members4/3/202117/6/2026
Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.
ModificadaAlta (7.2)1.2%—Strangerstudios Paid Memberships PRO20/5/202017/6/2026
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.4)2.8%💥 ExploitE-plugins WP Membership6/1/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for…
ModificadaAlta (8.8)2.0%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
ModificadaAlta (8.8)1.7%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.
ModificadaAlta (8.8)0.67%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
ModificadaMedia (5.4)0.71%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.
ModificadaMedia (5.4)1.2%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.
ModificadaCrítica (9.8)1.9%—Membersonic16/9/201917/6/2026
The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.
ModificadaMedia (6.1)0.95%—Ithemes Membership28/8/201917/6/2026
Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().