Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.34% | — | Heateor Social Login | 8/5/2024 | 17/6/2026 | Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. | |
| Aplazada | Media (4.3) | 0.39% | — | Idehweb Login With Phone NumberAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18. | |
| Aplazada | Media (5.9) | 0.36% | — | Maxim K Ajax Login AND Registration Modal Popup Inline FormAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim K AJAX Login and Registration modal popup + inline form allows Stored XSS.This issue affects AJAX Login and Registration modal popup + inline form: from n/a through 2.23. | |
| Aplazada | Media (6.5) | 0.31% | — | Vinod Dalvi Login Logout Register MenuAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vinod Dalvi Login Logout Register Menu allows Stored XSS.This issue affects Login Logout Register Menu: from n/a through 2.0. | |
| Analizada | Media (5.3) | 0.87% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed. | |
| Analizada | Alta (8.1) | 0.67% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components. | |
| Analizada | Media (5.5) | 0.23% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components. | |
| Analizada | Media (5.3) | 0.44% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections. | |
| Aplazada | Media (5.3) | 0.43% | — | Loginpress PROAI | 25/4/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpbuy Login AS User OR CustomerAI | 25/4/2024 | 17/6/2026 | Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8. | |
| Aplazada | Media (5.3) | 0.53% | — | Loginpress PROAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Thememylogin Theme MY LoginAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6. | |
| Aplazada | Media (4.3) | 0.20% | — | Pixelite Login With AjaxAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Pluginops Feather Login PageAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page.This issue affects Feather Login Page: from n/a through 1.1.5. | |
| Aplazada | Alta (8.8) | 0.31% | — | Idehweb Login With Phone NumberAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93. | |
| Aplazada | Alta (7.1) | 0.19% | — | Venugopal Change Default Login Logo URL AND TitleAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Change default login logo,url and title allows Cross-Site Scripting (XSS).This issue affects Change default login logo,url and title: from n/a through 2.0. | |
| Aplazada | Media (5.9) | 0.32% | — | Aminur Islam WP Login AND Logout RedirectAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Login and Logout Redirect allows Stored XSS.This issue affects WP Login and Logout Redirect: from n/a through 1.2. | |
| Aplazada | Media (5.9) | 0.34% | — | Phpbits Creative Studio Easy Login StylerAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Stored XSS.This issue affects Easy Login Styler – White Label Admin Login Page for WordPress: from n/a through 1.0.6. | |
| Aplazada | Media (6.5) | 0.33% | — | Cozmoslabs Passwordless LoginAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2. | |
| Analizada | Media (6.5) | 0.41% | — | Phpgurukul User Registration & Login AND User Management System | 14/3/2024 | 17/6/2026 | The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks. | |
| Modificada | Media (5.3) | 0.44% | — | Wpmet WP Social Login AND Register Social Counter | 13/3/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable… | |
| Analizada | Media (4.9) | 0.64% | — | Wp-buy Login AS User OR Customer (user Switching) | 11/3/2024 | 17/6/2026 | The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site. | |
| Analizada | Alta (7.5) | 0.83% | — | Keerti1924 PHP Mysql User Signup Login System | 7/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Crítica (9.8) | 0.60% | — | Keerti1924 PHP Mysql User Signup Login System | 7/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.37% | — | Nextendweb Nextend Social Login | 2/3/2024 | 17/6/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers,… |