Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.53% | — | Simple-membership-plugin Simple Membership | 21/3/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack | |
| Modificada | Media (4.7) | 0.47% | — | Simple-membership-plugin Simple Membership | 28/2/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 7/2/2022 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple Membership System Using PHP AND Ajax Project Simple Membership System Using PHP AND Ajax | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 27/12/2021 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 1.7% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 13/9/2021 | 17/6/2026 | The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages. | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Members | 8/7/2021 | 17/6/2026 | Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview. | |
| Modificada | Alta (7.8) | 1.7% | — | Samsung Members | 8/7/2021 | 17/6/2026 | Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview. | |
| Modificada | Baja (3.3) | 0.23% | — | Samsung Members | 8/7/2021 | 17/6/2026 | Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data. | |
| Modificada | Alta (7.5) | 3.1% | 💥 PoC | Samsung Members | 9/4/2021 | 17/6/2026 | An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account. | |
| Modificada | Media (5.4) | 0.66% | — | Wpdarko Team Members | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member. | |
| Modificada | Alta (8.8) | 2.0% | — | Strangerstudios Paid Memberships PRO | 18/3/2021 | 17/6/2026 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Members | 4/3/2021 | 17/6/2026 | Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider. | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Members | 4/3/2021 | 17/6/2026 | Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider. | |
| Modificada | Alta (7.2) | 1.2% | — | Strangerstudios Paid Memberships PRO | 20/5/2020 | 17/6/2026 | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | E-plugins WP Membership | 6/1/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for… | |
| Modificada | Alta (8.8) | 2.0% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. | |
| Modificada | Alta (8.8) | 1.7% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. | |
| Modificada | Alta (8.8) | 0.67% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | |
| Modificada | Media (5.4) | 0.71% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Membersonic | 16/9/2019 | 17/6/2026 | The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required. | |
| Modificada | Media (6.1) | 0.95% | — | Ithemes Membership | 28/8/2019 | 17/6/2026 | Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). |