Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

687 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.99%—Yoga Class Registration System Project Yoga Class Registration System24/6/202317/6/2026
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
ModificadaMedia (6.1)0.36%—User Registration & Login AND User Management System Project User Registration & Login AND User Management System21/6/202317/6/2026
User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
ModificadaMedia (4.8)0.37%—Aviplugins WP Register Profile With Shortcode12/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plugin <= 3.5.7 versions.
ModificadaMedia (6.5)0.42%—Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe3/6/202317/6/2026
The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible…
ModificadaMedia (5.4)0.76%—Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe3/6/202317/6/2026
El plugin Event Registration Calendar By vcita, versiones hasta la 3.9.1 inlcusive, y el plugin Online Payments – Get Paid with PayPal, Square &amp; Stripe, para WordPress son vulnerables a Cross-Site Scripting almacenado a través del parámetro "email" en versiones hasta la 1.3.1 inclusive, debido a un insuficiente…
ModificadaMedia (6.1)0.59%—Simplr Registration Form Plus+ Project Simplr Registration Form Plus+31/5/202317/6/2026
A vulnerability was found in Simplr Registration Form Plus+ Plugin up to 2.3.4 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.3.5 is able to address this issue. The…
ModificadaAlta (8.8)0.26%—Login AND Registration Attempts Limit Project Login AND Registration Attempts Limit25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in German Krutov LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin <= 2.1 versions.
ModificadaAlta (8.8)0.26%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaAlta (7.2)0.72%—Metagauss Registrationmagic16/5/202317/6/2026
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated…
ModificadaCrítica (9.8)1.3%—Metagauss Registrationmagic16/5/202317/6/2026
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any…
ModificadaMedia (6.5)0.33%—Enable/disable Auto Login When Register Project Enable/disable Auto Login When Register8/5/202317/6/2026
The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (4.8)0.37%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaCrítica (9.8)0.98%—ZM Ajax Login & Register Project ZM Ajax Login & Register15/4/202317/6/2026
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any…
ModificadaAlta (7.5)0.67%—Yoga Class Registration System Project Yoga Class Registration System14/4/202317/6/2026
Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.
ModificadaMedia (4.8)0.39%—Wpeverest User Registration6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.
ModificadaCrítica (9.8)0.78%—School Registration AND FEE System Project School Registration AND FEE System28/3/202317/6/2026
A vulnerability was found in SourceCodester School Registration and Fee System 1.0. It has been classified as critical. Affected is an unknown function of the file /bilal final/edit_stud.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the…
ModificadaCrítica (9.8)0.86%—School Registration AND FEE System Project School Registration AND FEE System28/3/202317/6/2026
A vulnerability was found in SourceCodester School Registration and Fee System 1.0 and classified as critical. This issue affects some unknown processing of the file /bilal final/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be…
ModificadaCrítica (9.8)0.78%—School Registration AND FEE System Project School Registration AND FEE System16/3/202317/6/2026
School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php.
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaMedia (6.1)0.60%—Yoga Class Registration System Project Yoga Class Registration System14/3/202317/6/2026
A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been declared as problematic. This vulnerability affects the function query of the file admin/user/list.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has…
ModificadaAlta (8.8)0.25%—Metagauss Registrationmagic13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
ModificadaAlta (7.2)0.71%—Yoga Class Registration System Project Yoga Class Registration System13/3/202317/6/2026
A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been classified as critical. This affects the function query of the file admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit…
ModificadaCrítica (9.8)0.63%—Email Registration Project Email Registration6/3/202316/6/2026
A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to sql injection. The attack can be initiated remotely. Upgrading to…
ModificadaBaja (3.7)0.62%—PostgresqlFedoraproject FedoraRedhat Integration Camel KRedhat Integration Camel Quarkus+23/3/202317/6/2026
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
ModificadaMedia (5.4)24%💥 ExploitGenetechsolutions PIE Register27/2/202317/6/2026
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
Orbitaley — Vulnerabilidades