Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.68%—Butlerblog Wp-members27/8/201917/6/2026
The wp-members plugin before 3.2.8 for WordPress has CSRF.
ModificadaAlta (8.8)0.70%—Simple-membership-plugin Simple Membership14/8/201917/6/2026
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
ModificadaMedia (6.1)0.92%—Simple-membership-plugin Simple Membership12/8/201917/6/2026
The simple-membership plugin before 3.5.7 for WordPress has XSS.
ModificadaAlta (8.8)3.1%💥 ExploitSimple-membership-plugin Simple Membership28/7/201917/6/2026
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
ModificadaAlta (8.8)1.3%—Samsung Members24/9/201817/6/2026
This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of…
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
ModificadaAlta (7.5)2.6%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
ModificadaMedia (4.3)1.6%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaAlta (7.5)0.97%—Auroradao Idex Membership3/5/201817/6/2026
The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables.
ModificadaMedia (4.8)0.62%—Ultimatemember User Profile & Membership23/4/201817/6/2026
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.
ModificadaAlta (8.8)0.67%—Ultimatemember User Profile & Membership23/4/201817/6/2026
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
ModificadaCrítica (9.8)2.0%💥 ExploitJextn Membership2/2/201817/6/2026
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.
ModificadaAlta (7.5)37%💥 ExploitJoomlatag Jtag Members Directory29/1/201817/6/2026
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
ModificadaMedia (6.1)2.1%—Strangerstudios Paid Memberships PRO23/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to…
ModificadaCrítica (9.8)2.3%—Ontraport Membership Simplified14/9/201717/6/2026
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.
ModificadaCrítica (9.8)2.3%—Ontraport Membership Simplified14/9/201717/6/2026
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.
ModificadaCrítica (9.8)17%💥 ExploitMembership Simplified Project Membership Simplified14/9/201717/6/2026
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
ModificadaMedia (6.1)1.8%—Butlerblog Wp-members7/7/201717/6/2026
Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)8.3%💥 ExploitWpmembership3/6/201517/6/2026
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.
ModificadaAlta (7.5)4.2%💥 ExploitYourmembers Project Yourmembers13/1/201517/6/2026
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to the default URI.
ModificadaMedia (5)18%💥 ExploitStrangerstudios Paid Memberships PRO28/11/201417/6/2026
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.
ModificadaMedia (5.4)0.27%—Mymembersfirst TN Members 1ST Fcu-rdc9/9/201417/6/2026
The TN Members 1st FCU-RDC (aka com.metova.cuae.tmffcu) application 1.0.28 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)0.97%—Crunchify Facebook Members5/5/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings.
Orbitaley — Vulnerabilidades