Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 546 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.22%—Wpusermanager WP User ManagerAI23/9/202623/9/2026
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
AplazadaMedia (4.3)0.20%—Wpusermanager WP User ManagerAI22/9/202622/9/2026
The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that reaches…
AplazadaCrítica (9.8)0.44%💥 PoCMetabox Meta BOX AIOAIMetabox Meta BOX Frontend SubmissionAIMetabox Meta BOX User ProfileAI22/9/202622/9/2026
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET…
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
AplazadaMedia (4.1)0.18%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
AplazadaAlta (8.1)0.38%—Ayecode UserswpAI19/9/202621/9/2026
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider…
Pendiente de análisisMedia (5.3)0.61%—Beautiful SoupAIFacelessuser Soup SieveAI17/9/202630/9/2026
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled…
Pendiente de análisisMedia (5.3)0.61%—Beautiful SoupAIFacelessuser Soup SieveAI17/9/202623/9/2026
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every…
AplazadaAlta (7.5)0.32%—Choose User Role AT RegistrationAI17/9/202618/9/2026
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle User ManagementAI15/9/202617/9/2026
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks…
AplazadaMedia (5.3)0.44%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI14/9/202616/9/2026
Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string…
Pendiente de análisisBaja (3.1)0.24%—Mediawiki CheckuserAIMediawikiAI14/9/202616/9/2026
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
AplazadaBaja (3.7)0.28%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile…
AplazadaAlta (7.5)0.32%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan…
AplazadaMedia (4.7)0.29%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.
AplazadaAlta (7.2)0.46%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to…
AplazadaAlta (8.8)0.42%—ADD User AutocompleteAI12/9/202614/9/2026
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.
AplazadaCrítica (9.3)0.37%—Avideo Customize UserAIWwbn AvideoAI11/9/202611/9/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra…
AplazadaAlta (8.1)0.41%—Ayecode UserswpAI11/9/202611/9/2026
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls…
AplazadaMedia (6.1)0.21%—User Access ManagerAI9/9/202611/9/2026
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
Pendiente de análisisAlta (7.8)0.16%—ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue…
Pendiente de análisisMedia (5.1)0.11%—ARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Valhall GPU Userspace Driver:…
AplazadaAlta (7.1)0.25%—100plugins Open User MAPAI8/9/20268/9/2026
Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
AplazadaAlta (7.2)0.42%—Codesigner User Profile BuilderAI7/9/20269/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This…
Orbitaley — Vulnerabilidades