Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)1.6%💥 ExploitLukashuser EKC Tournament Manager15/5/202517/6/2026
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
AnalizadaMedia (5.4)0.18%—Lukashuser EKC Tournament Manager15/5/202517/6/2026
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (5.4)0.18%—Lukashuser EKC Tournament Manager15/5/202517/6/2026
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (4.3)0.18%—Gamipress - Reset User15/5/202517/6/2026
The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (5.3)0.36%—Mooveagency User Activity Tracking AND LOG15/5/202517/6/2026
This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.
ModificadaCrítica (9.8)0.29%—Etoilewebdesign Front END Users15/5/202517/6/2026
Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through <= 3.2.35.
AnalizadaAlta (8.7)0.62%—Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+113/5/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All…
AnalizadaAlta (8.7)0.62%—Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+113/5/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All…
AnalizadaAlta (8.7)0.62%—Siemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation PortalSiemens User Management Component13/5/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All…
AplazadaMedia (5.3)0.46%—Moodle Catalyst User KEY Authentication PluginAI10/5/202517/6/2026
A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return leads to open redirect. The attack can be…
AplazadaMedia (6.5)0.22%—Faiyaz Alam User Login HistoryAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faiyaz Alam User Login History user-login-history allows Stored XSS.This issue affects User Login History: from n/a through <= 2.1.6.
AplazadaMedia (5.9)0.27%—Aharonyan WP Front User SubmitAIAleksanaharonyan Front EditorAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Stored XSS.This issue affects WP Front User Submit / Front Editor: from n/a through <= 5.0.6.
AplazadaMedia (5.9)0.27%—Arpad Lehel Matyus Terms Popup ON User LoginAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Árpád Lehel Mátyus Terms Popup On User Login terms-popup-on-user-login allows Stored XSS.This issue affects Terms Popup On User Login: from n/a through <= 2.0.8.
AplazadaMedia (5.3)0.42%—User Registration MembershipAI6/5/202517/6/2026
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key.…
AnalizadaCrítica (9.8)0.45%—User-xiangpeng Yaoqishan5/5/202517/6/2026
Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.
ModificadaCrítica (9.8)0.52%—Phpgurukul User Registration & Login AND User Management System28/4/20255/7/2026
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account…
AnalizadaAlta (8.8)1.5%—Webmin Usermin28/4/202517/6/2026
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
AplazadaMedia (4.3)0.17%—Tran Minh Quan Wpvn Username ChangerAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Trân Minh-Quân WPVN wpvn-username-changer allows Cross Site Request Forgery.This issue affects WPVN: from n/a through <= 0.7.8.
AplazadaMedia (5.9)0.27%—Ralf Hortt Confirm User RegistrationAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ralf Hortt Confirm User Registration confirm-user-registration allows Stored XSS.This issue affects Confirm User Registration: from n/a through <= 2.1.5.
ModificadaMedia (6.1)0.29%—Wpeverest User Registration & Membership24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through < 4.2.0.
AnalizadaAlta (8.1)9.5%💥 ExploitWpeverest User Registration & Membership22/4/202517/6/2026
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.
AnalizadaAlta (7.1)0.54%💥 ExploitEtoilewebdesign Front END Users22/4/202517/6/2026
The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (4.3)0.15%—Wpeverest User RegistrationAI19/4/202517/6/2026
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3. This is due to missing or incorrect nonce validation on the user_registration_pro_delete_account() function. This…
AplazadaAlta (7.1)0.15%—Devrix Restrict User RegistrationAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DevriX Restrict User Registration restrict-user-registration allows Stored XSS.This issue affects Restrict User Registration: from n/a through <= 1.0.1.
AplazadaAlta (7.1)0.29%—Ivan82 User ListAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivan82 User List user-list allows Reflected XSS.This issue affects User List: from n/a through <= 1.5.1.
Orbitaley — Vulnerabilidades