Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.98% | 💥 PoC | Solwininfotech User Activity LOG | 4/9/2023 | 17/6/2026 | El plugin de WordPress User Activity Log anterior a la versión 1.6.7 recupera direcciones IP de clientes a partir de cabeceras potencialmente no fiables, lo que permite a un atacante manipular su valor. Esto puede utilizarse para ocultar el origen del tráfico malicioso. | |
| Modificada | Media (4.3) | 0.52% | — | Solwininfotech User Activity LOG | 4/9/2023 | 17/6/2026 | El complemento de WordPress Registro de Actividad del Usuario anterior a 1.6.6 carece de la autorización adecuada al exportar sus registros de actividad, lo que permite a cualquier usuario autenticado, como un suscriptor, realizar dicha acción y recuperar PII, como direcciones de correo electrónico. | |
| Modificada | Media (4.3) | 0.25% | — | Mooveagency User Activity Tracking AND LOG | 30/8/2023 | 17/6/2026 | El plugin de WordPress User Activity Tracking and Log anterior a 4.0.9 no dispone de comprobaciones CSRF adecuadas al gestionar su licencia, lo que podría permitir a los atacantes hacer que los administradores logueados actualicen y desactiven la licencia del plugin mediante ataques CSRF. | |
| Modificada | Media (4.3) | 0.48% | — | Riverforest-wp ALL Users Messenger | 30/8/2023 | 17/6/2026 | El plugin All Users Messenger WordPress hasta la versión 1.24 no impide a los usuarios no administradores borrar mensajes del mensajero para todos los usuarios. | |
| Modificada | Media (5.3) | 0.59% | — | Alexanderschneider User Access Manager | 30/8/2023 | 17/6/2026 | El plugin de WordPress User Access Manager anterior a la versión 2.2.18 prioriza la obtención de la IP de un visitante a partir de ciertas cabeceras HTTP sobre REMOTE_ADDR de PHP, lo que hace posible que los atacantes accedan a contenido restringido en determinadas situaciones. | |
| Modificada | Media (5.4) | 0.54% | — | Webmin Usermin | 29/8/2023 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via options for the host value while editing the host options. | |
| Modificada | Media (4.3) | 0.74% | — | Froger WP Remote Users Sync | 16/8/2023 | 17/6/2026 | The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to… | |
| Modificada | Media (5.4) | 0.73% | — | Froger WP Remote Users Sync | 16/8/2023 | 17/6/2026 | The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from… | |
| Modificada | Media (5.4) | 0.42% | — | Plugin-planet User Submitted Posts | 15/8/2023 | 17/6/2026 | El plugin User Submitted Posts para WordPress es vulnerable a Cross-Site Scripting (XSS) Almacenado a través del parámetro 'user-submitted-content' en versiones hasta, e incluyendo, 20230809 debido a insuficiente sanitización de entrada y escape de salida. Esto hace posible que atacantes no autenticados inyecten… | |
| Modificada | Crítica (9.8) | 1.0% | — | Solwininfotech User Activity LOG | 14/8/2023 | 17/6/2026 | The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks. | |
| Modificada | Alta (8.1) | 0.44% | — | Nextcloud User Oidc | 10/8/2023 | 17/6/2026 | user_oidc proporciona el backend de usuario de conexión OIDC para Nextcloud, una plataforma en la nube de código abierto. A partir de la versión 1.0.0 y antes de la versión 1.3.3, un atacante que haya obtenido al menos acceso de lectura a una instantánea de la base de datos puede suplantar la identidad del servidor… | |
| Modificada | Media (4.8) | 0.54% | — | Nextcloud User Oidc | 10/8/2023 | 17/6/2026 | user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the issuer would have allowed an attacker to perform a man-in-the-middle attack returning corrupted or known token they also have access to.… | |
| Modificada | Alta (7.2) | 0.90% | — | Solwininfotech User Activity LOG | 24/7/2023 | 17/6/2026 | The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Alta (7.2) | 0.93% | — | Webtoffee Import Export Wordpress Users | 18/7/2023 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop… | |
| Modificada | Alta (8.8) | 0.32% | — | Etoilewebdesign Front END Users | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Inactive User Deleter Project Inactive User Deleter | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Korol Yuriy aka Shra Inactive User Deleter plugin <= 1.59 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Wpeverest User Registration | 13/7/2023 | 17/6/2026 | El plugin User Registration para WordPress es vulnerable a la inyección de objetos PHP en versiones hasta la 3.0.1 inclusive a través de la deserialización de la entrada no fiable del parámetro "profile-pic-url". Esto permite a atacantes autenticados, con permisos de nivel de suscriptor y superiores, inyectar un… | |
| Modificada | Crítica (9.9) | 1.7% | — | Wpeverest User Registration | 13/7/2023 | 17/6/2026 | El plugin User Registration para WordPress es vulnerable a la carga de archivos arbitrarios debido a una clave de cifrado codificada y a la falta de validación del tipo de archivo en la función "ur_upload_profile_pic" en las versiones hasta la 3.0.2 inclusive. Esto hace posible que atacantes autenticados con… | |
| Modificada | Media (5.4) | 0.51% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 6/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field. | |
| Modificada | Media (6.1) | 0.41% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 29/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | |
| Modificada | Media (5.4) | 0.34% | — | Techtime User Management | 26/6/2023 | 17/6/2026 | The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24. | |
| Modificada | Media (6.1) | 0.36% | — | User Registration & Login AND User Management System Project User Registration & Login AND User Management System | 21/6/2023 | 17/6/2026 | User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php. | |
| Modificada | Media (4.8) | 0.40% | — | Extra User Details Project Extra User Details | 20/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Vadym K. Extra User Details plugin <= 0.5 versions. | |
| Modificada | Crítica (9.8) | 2.3% | — | Plugin-planet User Submitted Posts | 7/6/2023 | 17/6/2026 | The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may… | |
| Modificada | Alta (8.8) | 1.4% | — | WP User Switch Project WP User Switch | 6/6/2023 | 17/6/2026 | The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with… |