Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.27%—Reputeinfosystems Armember8/1/202417/6/2026
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: n/a.
ModificadaMedia (6.5)0.44%—Butlerblog Wp-members4/1/202417/6/2026
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails,…
ModificadaMedia (5.4)0.61%—Carmelogarcia Intern Membership Management System28/12/202317/6/2026
A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /user_registration/ of the component User Registration. The manipulation of the argument userName/firstName/lastName/userEmail with the input…
ModificadaCrítica (9.8)0.72%—Carmelogarcia Intern Membership Management System28/12/202317/6/2026
A vulnerability was found in code-projects Intern Membership Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user_registration/ of the component User Registration. The manipulation of the argument userName leads to sql injection. The exploit has been…
ModificadaMedia (6.1)0.46%—Simple-membership-plugin Simple Membership19/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8.
ModificadaAlta (8.8)51%—Strangerstudios Paid Memberships PRO18/11/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or…
ModificadaMedia (4.8)0.39%—Dazzlersoft Team Members Showcase16/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 versions.
ModificadaAlta (7.5)0.69%—Memberscard Project Memberscard14/11/202317/6/2026
An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
ModificadaCrítica (9.8)0.64%—Reputeinfosystems Armember3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership allows SQL Injection.This issue affects ARMember: from n/a through 3.4.11.
ModificadaMedia (5.4)0.45%—Strangerstudios Memberlite Shortcodes31/10/202317/6/2026
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaMedia (6.1)0.11%—Silabs Emberznet SDK26/10/202317/6/2026
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.
ModificadaAlta (8.2)0.58%—Linecorp Fukunaga Memberscard25/10/202317/6/2026
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
ModificadaMedia (4.8)0.46%—Armemberplugin Armember20/10/202317/6/2026
The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
ModificadaMedia (4.3)0.39%—Strangerstudios Paid Memberships PRO20/10/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they…
ModificadaCrítica (9.8)0.69%—Silabs Emberznet4/10/202317/6/2026
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from…
ModificadaCrítica (9.8)0.82%—Razormist Simple Membership System29/9/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (6.5)0.45%—Kokoroe Members Card Project Kokoroe Members Card20/9/202317/6/2026
An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages.
ModificadaMedia (6.5)0.46%—THE B Members Card Project THE B Members Card18/9/20239/7/2026
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
ModificadaAlta (7.5)0.61%—Razormist Simple Membership System17/9/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.61%—Razormist Simple Membership System9/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been rated as critical. This issue affects some unknown processing of the file delete_member.php. The manipulation of the argument mem_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.74%—Razormist Simple Membership System9/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.60%—Razormist Simple Membership System8/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been classified as critical. This affects an unknown part of the file club_edit_query.php. The manipulation of the argument club_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaMedia (6.1)0.57%—Simple-membership-plugin Simple Membership6/9/202317/6/2026
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could inject arbitrary web scripts into pages…
ModificadaMedia (4.8)0.36%—Minorange Wordpress Yourmembership Single Sign-on1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Login plugin <= 1.1.3 versions.
ModificadaMedia (4.3)0.34%—Samsung Members10/8/202317/6/2026
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.
Orbitaley — Vulnerabilidades