Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

648 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.19%—Netiq Client Login Extension29/2/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login Extension: 4.6.
ModificadaMedia (5.4)0.39%—Webfactoryltd WP Login Lockdown29/2/202417/6/2026
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to export…
AnalizadaMedia (6.1)0.99%💥 PoCPhpgurukul User Registration & Login AND User Management System28/2/202417/6/2026
Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.
AnalizadaCrítica (9.8)0.66%—Keerti1924 PHP Mysql User Signup Login System21/2/202417/6/2026
A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaCrítica (9.8)0.81%—Keerti1924 PHP Mysql User Signup Login System21/2/202417/6/2026
A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.4)0.58%—Keerti1924 PHP Mysql User Signup Login System21/2/202417/6/2026
A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument username with the input <script>alert("xss")</script> leads to cross site scripting. It is possible to launch the…
ModificadaCrítica (9.8)1.8%💥 PoCMiniorange Web3 - Crypto Wallet Login & NFT Token Gating12/2/202417/6/2026
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an…
ModificadaMedia (5.4)0.32%—Heateor Social Login10/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30.
ModificadaMedia (6.1)0.41%—Rems QR Code Login System31/1/202417/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Login System 1.0. Affected by this issue is some unknown functionality of the file add-user.php. The manipulation of the argument qr-code leads to cross site scripting. The attack may be launched remotely. VDB-252470 is the…
ModificadaAlta (7.2)1.2%💥 PoCRemyandrade Login System With Email Verification29/1/202417/6/2026
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
ModificadaMedia (6.5)0.56%—Wpmet WP Social Login AND Register Social Counter19/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0.
ModificadaCrítica (9.8)1.00%—Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+1119/1/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long…
ModificadaAlta (8.8)0.44%—Themeinprogress WIP Custom Login17/1/202417/6/2026
Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.
ModificadaMedia (5.4)0.43%—Limitloginattempts Limit Login Attempts Reloaded11/1/202417/6/2026
The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (7.2)0.58%—Webfactoryltd WP Login Lockdown29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06.
ModificadaMedia (6.1)0.48%—Swapnilpatil Login AND Logout Redirect19/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.
ModificadaAlta (8.8)0.28%—Wpdoctor Woocommerce Login Redirect18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect.This issue affects WooCommerce Login Redirect: from n/a through 2.2.4.
ModificadaCrítica (9.8)0.89%—Thememylogin 2FA18/12/202317/6/2026
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
ModificadaAlta (8.8)0.26%—Saintsystems Disable User Login18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Saint Systems Disable User Login.This issue affects Disable User Login: from n/a through 1.3.7.
ModificadaMedia (4.8)0.43%—Wpajans WP NOT Login Hide11/12/202317/6/2026
The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)0.80%—Remyandrade User Registration AND Login System2/12/202317/6/2026
A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument user leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaMedia (5.4)0.60%—Remyandrade User Registration AND Login System1/12/202317/6/2026
A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument first_name leads to cross site scripting. The attack can be launched…
ModificadaMedia (6.1)0.61%—Remyandrade User Registration AND Login System1/12/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 1.0. Affected is an unknown function of the file /endpoint/delete-user.php. The manipulation of the argument user leads to cross site scripting. It is possible to launch the attack remotely. The exploit…
ModificadaMedia (4.3)0.45%—Limitloginattempts Limit Login Attempts Reloaded27/11/202317/6/2026
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
ModificadaAlta (8.8)0.31%—Yoohooplugins When Last Login22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Yoohoo Plugins When Last Login plugin <= 1.2.1 versions.