Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.42% | — | Phpgurukul Online Marriage Registration System | 11/11/2024 | 17/6/2026 | A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter. | |
| Analizada | Crítica (9.8) | 0.51% | — | Phpgurukul Online Marriage Registration System | 11/11/2024 | 17/6/2026 | A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter. | |
| Analizada | Crítica (9.8) | 1.5% | 💥 PoC | Metagauss Registrationmagic | 9/11/2024 | 17/6/2026 | The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password.… | |
| Analizada | Crítica (9.6) | 0.69% | — | Roundupwp Registrations FOR THE Events Calendar | 8/11/2024 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. | |
| Aplazada | Media (6.4) | 0.39% | — | Roundupwp Registrations FOR THE Events CalendarAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Wpmet WP Social Login AND Register Social CounterAI | 26/10/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any… | |
| Modificada | Alta (8.8) | 0.23% | — | APA Register Newsletter Form | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aatmaadhikari APA Register Newsletter Form apa-register-newsletter-form allows SQL Injection.This issue affects APA Register Newsletter Form: from n/a through <= 1.0.0. | |
| Modificada | Crítica (9.8) | 0.47% | — | Madirisalmanaashish Adding Drop Down Roles IN Registration | 17/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.8) | 0.53% | — | SK Buddypress Better RegistrationAI | 16/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a through <= 1.6. | |
| Analizada | Crítica (9.8) | 0.60% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter. | |
| Analizada | Alta (7.6) | 0.42% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.58% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request. | |
| Analizada | Media (5.5) | 0.18% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. | |
| Analizada | Media (5.3) | 0.46% | — | Rems Profile Registration Without Reload/refresh | 10/10/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/address/company_name/job_title/jobDescriptionparameter leads to… | |
| Analizada | Media (5.3) | 0.54% | — | Rems Profile Registration Without Reload/refresh | 23/9/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0. This affects an unknown part of the file del.php of the component GET Parameter Handler. The manipulation of the argument list leads to sql injection. It is possible to initiate the attack remotely.… | |
| Analizada | Media (5.3) | 0.46% | — | Rems Profile Registration Without Reload/refresh | 23/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add.php of the component Registration Form. The manipulation of the argument full_name leads to cross site scripting. The… | |
| Aplazada | Alta (8.8) | 0.44% | — | Favethemes Houzez Login RegisterAI | 17/9/2024 | 17/6/2026 | Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5. | |
| Analizada | Alta (8.8) | 0.44% | — | Roundupwp Registrations FOR THE Events Calendar | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2. | |
| Analizada | Media (6.1) | 0.27% | — | Metagauss Registrationmagic | 19/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects RegistrationMagic: from n/a through 6.0.1.0. | |
| Analizada | Media (5.3) | 0.42% | — | Oretnom23 Yoga Class Registration System | 18/8/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Yoga Class Registration System 1.0. Affected is an unknown function of the file /php-ycrs/classes/SystemSettings.php. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Media (6.1) | 0.31% | — | Teleogistic Invite Anyone | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7. | |
| Aplazada | Media (6.5) | 0.21% | — | Login AND Registration Attempts LimitAI | 17/8/2024 | 17/6/2026 | The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For… | |
| Analizada | Media (5.3) | 0.58% | — | Oretnom23 Yoga Class Registration System | 16/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=categories/view_category. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.46% | — | Oretnom23 Yoga Class Registration System | 16/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/inquiries/view_inquiry.php. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely. The… |