Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.7% | — | Favethemes Houzez Login RegisterAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3. | |
| Aplazada | Media (5.9) | 0.36% | — | Maxim K Ajax Login AND Registration Modal Popup Inline FormAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim K AJAX Login and Registration modal popup + inline form allows Stored XSS.This issue affects AJAX Login and Registration modal popup + inline form: from n/a through 2.23. | |
| Modificada | Media (6.1) | 0.33% | — | Metagauss Registrationmagic | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.3.2.0. | |
| Aplazada | Media (6.5) | 0.31% | — | Vinod Dalvi Login Logout Register MenuAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vinod Dalvi Login Logout Register Menu allows Stored XSS.This issue affects Login Logout Register Menu: from n/a through 2.0. | |
| Aplazada | Media (6.5) | 0.91% | — | Wpeverest User RegistrationAI | 2/5/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.94% | — | Wpeverest User RegistrationAI | 2/5/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated… | |
| Aplazada | Media (6.8) | 0.69% | — | Openshift Image Registry OperatorAI | 1/5/2024 | 17/6/2026 | An information disclosure flaw was found in OpenShift's internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. An attacker controlling an account that has high enough permissions to obtain pod… | |
| Aplazada | Alta (7.3) | 0.34% | — | Redhat Mirror RegistryAIRedhat QuayAI | 25/4/2024 | 17/6/2026 | A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance. | |
| Aplazada | Alta (7.3) | 0.34% | — | Redhat QuayAIRedhat Mirror RegistryAI | 25/4/2024 | 17/6/2026 | A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database. | |
| Modificada | Media (6.5) | 0.43% | — | Redhat Mirror Registry | 25/4/2024 | 17/6/2026 | A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same database secret key. This flaw allows a… | |
| Analizada | Alta (8.8) | 0.52% | — | Redhat Mirror Registry | 25/4/2024 | 17/6/2026 | A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This flaw allows a malicious actor to craft… | |
| Modificada | Media (6.5) | 0.36% | — | Metagauss Registrationmagic | 24/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.1.9.2. | |
| Modificada | Alta (7.5) | 0.46% | — | Metagauss Registrationmagic | 24/4/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2. | |
| Aplazada | Media (4.3) | 0.20% | — | Arnan DE Gans No-bot RegistrationAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Arnan de Gans No-Bot Registration.This issue affects No-Bot Registration: from n/a through 1.9.1. | |
| Modificada | Crítica (9.8) | 0.40% | — | Metagauss Registrationmagic | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9. | |
| Aplazada | Media (4.3) | 0.40% | — | Event Tickets AND RegistrationAI | 9/4/2024 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street… | |
| Modificada | Alta (8.8) | 0.89% | — | Metagauss Registrationmagic | 9/4/2024 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.82% | — | Metagauss Registrationmagic | 9/4/2024 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of the RM_Form shortcode in all versions up to, and including, 5.3.1.0 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Media (6.6) | 0.28% | — | Nmap ImporterAIMicrosoft Windows RegistryAI | 8/4/2024 | 17/6/2026 | The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry. | |
| Modificada | Media (5.4) | 0.70% | — | Campcodes Online Marriage Registration System | 28/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form. | |
| Modificada | Alta (8.8) | 0.61% | — | Wpeverest User Registration & Membership | 26/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. | |
| Modificada | Media (4.3) | 0.22% | — | Metagauss Registrationmagic | 26/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0. | |
| Analizada | Media (6.1) | 0.54% | — | Campcodes Online Marriage Registration System | 22/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.4) | 0.51% | — | Campcodes Online Marriage Registration System | 22/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/application-bwdates-reports-details.php. The manipulation of the argument fromdate leads to cross site scripting. It is possible to initiate the attack… | |
| Analizada | Media (6.1) | 0.54% | — | Campcodes Online Marriage Registration System | 22/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Marriage Registration System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The exploit… |