Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.22%—Jenkins User1st Utester9/7/202517/6/2026
Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
AplazadaMedia (5.4)0.18%—Mediawiki CheckuserAI8/7/202517/6/2026
The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to inject JavaScript through the uselang=x-xss language override mechanism. This issue affects Mediawiki - CheckUser extension:…
AplazadaMedia (5.4)0.18%—Mediawiki CheckuserAI8/7/202517/6/2026
The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit this by appending ?uselang=x-xss to the URL, causing reflected XSS when the UI renders affected message keys. This…
AplazadaMedia (5.4)0.18%—Mediawiki CheckuserAI7/7/202517/6/2026
The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X…
AnalizadaAlta (8.8)0.86%—Gameusers Game Users Share Button28/6/202517/6/2026
The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in all versions up to, and including, 1.3.0. This makes it possible for Subscriber-level attackers to add arbitrary file paths (such as…
AplazadaAlta (7.5)0.62%—Case-themes CtusersAI27/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case-Themes CTUsers ctuser allows PHP Local File Inclusion.This issue affects CTUsers: from n/a through <= 1.0.0.
AplazadaAlta (7.1)0.26%—Aharonyan WP Front User SubmitAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Reflected XSS.This issue affects WP Front User Submit / Front Editor: from n/a through <= 4.9.3.
AplazadaAlta (7.1)0.15%—Aharonyan WP Front User SubmitAIAleksanaharonyan Front EditorAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Cross Site Request Forgery.This issue affects WP Front User Submit / Front Editor: from n/a through <= 5.0.6.
AplazadaAlta (7.1)0.13%—Vgstef WP User Stylesheet SwitcherAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows Stored XSS.This issue affects WP User Stylesheet Switcher: from n/a through <= v2.2.0.
AplazadaMedia (4.3)0.28%—Mahabub81 User Roles AND CapabilitiesAI20/6/202517/6/2026
Missing Authorization vulnerability in mahabub81 User Roles and Capabilities user-roles-and-capabilities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Roles and Capabilities: from n/a through <= 1.2.6.
AplazadaMedia (4.3)0.28%—Wpeventmanager WP User Profile AvatarAI20/6/202517/6/2026
Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6.
AplazadaMedia (5.9)0.63%—Userproplugin UserproAI14/6/202517/6/2026
The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can…
AplazadaAlta (7.1)0.20%—Rust UsersAI6/6/202517/6/2026
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.
AnalizadaMedia (6.1)0.16%—Hk1993 WP Online Users Stats6/6/202517/6/2026
The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged…
AnalizadaMedia (4.9)0.37%—Hk1993 WP Online Users Stats6/6/202517/6/2026
The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (5.4)0.19%—Anti Spam Spam Protection Block Spam Users Comments FormsAI6/6/202517/6/2026
The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for…
AplazadaAlta (8.1)0.81%—Wedevs WP User FrontendAI5/6/202517/6/2026
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AplazadaAlta (8.8)0.92%💥 PoCWP User Frontend PROAI5/6/202517/6/2026
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on…
AnalizadaAlta (7.8)0.16%—ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver2/6/202517/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL…
AnalizadaMedia (6.9)0.48%—Razormist Display Username After Login31/5/202517/6/2026
A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AplazadaAlta (7.1)0.28%—Khaled User MetaAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Khaled User Meta user-meta allows Reflected XSS.This issue affects User Meta: from n/a through <= 3.1.2.
AplazadaAlta (8.6)0.35%—Typo3AIStanislas Rolland SR Feuser RegisterAI21/5/202517/6/2026
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
AplazadaCrítica (10)0.71%—Stanislas Rolland SR Feuser RegisterAI21/5/202517/6/2026
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.
AplazadaCrítica (9.8)0.24%—Danny Vink User Profile Meta ManagerAI19/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affects User Profile Meta Manager: from n/a through <= 1.02.
AnalizadaMedia (6.9)0.51%—Phpgurukul User Registration & Login AND User Management System19/5/202517/6/2026
A vulnerability has been found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. This vulnerability affects unknown code of the file /edit-profile.php. The manipulation of the argument Contact leads to sql injection. The attack can be initiated remotely. The exploit has…
Orbitaley — Vulnerabilidades