Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.68% | — | Butlerblog Wp-members | 27/8/2019 | 17/6/2026 | The wp-members plugin before 3.2.8 for WordPress has CSRF. | |
| Modificada | Alta (8.8) | 0.70% | — | Simple-membership-plugin Simple Membership | 14/8/2019 | 17/6/2026 | The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues. | |
| Modificada | Media (6.1) | 0.92% | — | Simple-membership-plugin Simple Membership | 12/8/2019 | 17/6/2026 | The simple-membership plugin before 3.5.7 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 3.1% | 💥 Exploit | Simple-membership-plugin Simple Membership | 28/7/2019 | 17/6/2026 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | |
| Modificada | Alta (8.8) | 1.3% | — | Samsung Members | 24/9/2018 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of… | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | — | Auroradao Idex Membership | 3/5/2018 | 17/6/2026 | The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables. | |
| Modificada | Media (4.8) | 0.62% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | |
| Modificada | Alta (8.8) | 0.67% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | Jextn Membership | 2/2/2018 | 17/6/2026 | SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request. | |
| Modificada | Alta (7.5) | 37% | 💥 Exploit | Joomlatag Jtag Members Directory | 29/1/2018 | 17/6/2026 | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. | |
| Modificada | Media (6.1) | 2.1% | — | Strangerstudios Paid Memberships PRO | 23/10/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to… | |
| Modificada | Crítica (9.8) | 2.3% | — | Ontraport Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ontraport Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function. | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Membership Simplified Project Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges. | |
| Modificada | Media (6.1) | 1.8% | — | Butlerblog Wp-members | 7/7/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 8.3% | 💥 Exploit | Wpmembership | 3/6/2015 | 17/6/2026 | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Yourmembers Project Yourmembers | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to the default URI. | |
| Modificada | Media (5) | 18% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 28/11/2014 | 17/6/2026 | Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php. | |
| Modificada | Media (5.4) | 0.27% | — | Mymembersfirst TN Members 1ST Fcu-rdc | 9/9/2014 | 17/6/2026 | The TN Members 1st FCU-RDC (aka com.metova.cuae.tmffcu) application 1.0.28 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 0.97% | — | Crunchify Facebook Members | 5/5/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings. |