Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

687 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.46%—Registration Form FOR WoocommerceAI10/9/202610/9/2026
The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can…
AplazadaAlta (8.8)0.41%—Metagauss RegistrationmagicAI5/9/20268/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user…
AplazadaMedia (5.3)0.32%—Metagauss RegistrationmagicAI2/9/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
AplazadaMedia (5.3)0.32%—Metagauss RegistrationmagicAI2/9/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
AplazadaAlta (7.5)0.37%—Metagauss RegistrationmagicAI2/9/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
AplazadaAlta (7.4)0.39%—Metagauss RegistrationmagicAI31/8/20261/9/2026
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
AplazadaAlta (7.1)0.25%💥 PoCRegistrationmagic Registration MagicAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
AplazadaAlta (7.5)0.24%—TBC Technology INC KitlogisticAI31/8/20261/9/2026
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.
AplazadaCrítica (9.8)0.40%—Custom User Registration Fields FOR WoocommerceAI29/8/20261/9/2026
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in…
AplazadaAlta (7.2)0.46%—User Registration AND MembershipAI28/8/202628/8/2026
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change…
AplazadaMedia (4.3)0.25%—User Registration MembershipAI28/8/202628/8/2026
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an…
AplazadaMedia (5.5)0.27%—Metagauss RegistrationmagicAI26/8/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
AplazadaAlta (7.7)0.40%—Typo3AITypo3 Event RegistrationAI25/8/202626/8/2026
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects.…
AplazadaCrítica (9.8)0.61%—User Registration Membership PROAI20/8/202620/8/2026
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
AplazadaMedia (5.5)0.53%—Code-projects Login Registration SystemAI20/8/202621/8/2026
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely.…
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
AplazadaCrítica (9.8)0.56%—Registrationmagic Registration MagicAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
AplazadaBaja (2.1)0.45%—Webkul BagistoAI18/8/202620/8/2026
A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack…
AplazadaBaja (2.1)0.37%—Webkul BagistoAI18/8/202620/8/2026
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public…
AplazadaBaja (2)0.43%—Webkul BagistoAI17/8/202620/8/2026
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has…
AplazadaBaja (2.1)0.38%—Webkul BagistoAI17/8/202620/8/2026
A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is…
AplazadaBaja (2)0.33%—Webkul BagistoAI17/8/202620/8/2026
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been…
AplazadaBaja (2.1)0.40%—Webkul BagistoAI17/8/202620/8/2026
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched…
AplazadaBaja (2.1)0.37%—Webkul BagistoAI17/8/202620/8/2026
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit…