Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

648 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.34%—Heateor Social Login8/5/202417/6/2026
Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
AplazadaMedia (4.3)0.39%—Idehweb Login With Phone NumberAI6/5/202417/6/2026
Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18.
AplazadaMedia (5.9)0.36%—Maxim K Ajax Login AND Registration Modal Popup Inline FormAI3/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim K AJAX Login and Registration modal popup + inline form allows Stored XSS.This issue affects AJAX Login and Registration modal popup + inline form: from n/a through 2.23.
AplazadaMedia (6.5)0.31%—Vinod Dalvi Login Logout Register MenuAI3/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vinod Dalvi Login Logout Register Menu allows Stored XSS.This issue affects Login Logout Register Menu: from n/a through 2.0.
AnalizadaMedia (5.3)0.87%—Logint Lomag Warehouse Management1/5/202417/6/2026
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.
AnalizadaAlta (8.1)0.67%—Logint Lomag Warehouse Management1/5/202417/6/2026
SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.
AnalizadaMedia (5.5)0.23%—Logint Lomag Warehouse Management1/5/202417/6/2026
An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.
AnalizadaMedia (5.3)0.44%—Logint Lomag Warehouse Management1/5/202417/6/2026
The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections.
AplazadaMedia (5.3)0.43%—Loginpress PROAI25/4/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0.
AplazadaCrítica (9.8)0.70%—Wpbuy Login AS User OR CustomerAI25/4/202417/6/2026
Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.
AplazadaMedia (5.3)0.53%—Loginpress PROAI24/4/202417/6/2026
Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.
AplazadaMedia (4.3)0.34%—Thememylogin Theme MY LoginAI17/4/202417/6/2026
Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6.
AplazadaMedia (4.3)0.20%—Pixelite Login With AjaxAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1.
AplazadaMedia (4.3)0.21%—Pluginops Feather Login PageAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page.This issue affects Feather Login Page: from n/a through 1.1.5.
AplazadaAlta (8.8)0.31%—Idehweb Login With Phone NumberAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.
AplazadaAlta (7.1)0.19%—Venugopal Change Default Login Logo URL AND TitleAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Change default login logo,url and title allows Cross-Site Scripting (XSS).This issue affects Change default login logo,url and title: from n/a through 2.0.
AplazadaMedia (5.9)0.32%—Aminur Islam WP Login AND Logout RedirectAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Login and Logout Redirect allows Stored XSS.This issue affects WP Login and Logout Redirect: from n/a through 1.2.
AplazadaMedia (5.9)0.34%—Phpbits Creative Studio Easy Login StylerAI7/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Stored XSS.This issue affects Easy Login Styler – White Label Admin Login Page for WordPress: from n/a through 1.0.6.
AplazadaMedia (6.5)0.33%—Cozmoslabs Passwordless LoginAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.
AnalizadaMedia (6.5)0.41%—Phpgurukul User Registration & Login AND User Management System14/3/202417/6/2026
The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.
ModificadaMedia (5.3)0.44%—Wpmet WP Social Login AND Register Social Counter13/3/202417/6/2026
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable…
AnalizadaMedia (4.9)0.64%—Wp-buy Login AS User OR Customer (user Switching)11/3/202417/6/2026
The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.
AnalizadaAlta (7.5)0.83%—Keerti1924 PHP Mysql User Signup Login System7/3/202417/6/2026
A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalizadaCrítica (9.8)0.60%—Keerti1924 PHP Mysql User Signup Login System7/3/202417/6/2026
A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaMedia (5.4)0.37%—Nextendweb Nextend Social Login2/3/202417/6/2026
The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers,…
Orbitaley — Vulnerabilidades