Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Wisetr User Email Verification FOR Woocommerce3/6/202317/6/2026
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to…
ModificadaMedia (5.4)0.36%—Display Post Meta, Term Meta, Comment Meta, AND User Meta Project Display Post Meta, Term Meta, Comment Meta, AND User Meta31/5/202317/6/2026
The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post metadata in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)0.85%—Nextcloud User Oidc25/5/202317/6/2026
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
ModificadaAlta (8.8)0.26%—User-meta User Meta Manager22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in User Meta Manager plugin <= 3.4.9 versions.
ModificadaMedia (5.4)0.36%—Theguidex User IP AND Location18/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TheGuideX User IP and Location plugin <= 2.2 versions.
ModificadaAlta (7.5)1.7%💥 PoCFacelessuser Pymdown Extensions15/5/202317/6/2026
PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when using include file syntax. By using the syntax `--8<--"/etc/passwd"` or `--8<--"/proc/self/environ"` the content of these files will be rendered in the generated…
ModificadaMedia (4.8)0.37%—Useragent-spy Project Useragent-spy11/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fernando Briano UserAgent-Spy plugin <= 1.3.1 versions.
ModificadaMedia (6.1)0.38%—I13websolution Mass Email TO Users10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <= 1.1.4 versions.
ModificadaMedia (4.8)0.39%—Userlike9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Voswinkel Userlike – WordPress Live Chat plugin <= 2.2 versions.
ModificadaMedia (4.8)0.37%—Eyes Only User Access Shortcode Project Eyes Only User Access Shortcode3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Thom Stark Eyes Only: User Access Shortcode plugin <= 1.8.2 versions.
ModificadaMedia (6.1)0.41%—User Meta Manager Project User Meta Manager23/4/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Jason Lau User Meta Manager plugin <= 3.4.9 versions.
ModificadaMedia (4.3)0.48%—Oracle User Management18/4/202317/6/2026
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful…
ModificadaMedia (5.4)0.64%—Export User Project Export User14/4/202317/6/2026
The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
ModificadaMedia (4.8)0.39%—Wpeverest User Registration6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.
ModificadaMedia (5.4)0.33%—Nextcloud User Oidc4/4/202317/6/2026
user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request to their second request. Users should…
ModificadaAlta (8.8)0.41%—Bestwebsoft User Role3/4/202317/6/2026
The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
ModificadaMedia (4.8)0.41%—Usersnap29/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions.
ModificadaMedia (4.3)0.40%—Cloudfoundry User Account AND Authentication28/3/202317/6/2026
This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider…
ModificadaAlta (8.8)0.91%—E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+727/3/202317/6/2026
The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before…
ModificadaAlta (7.2)1.5%💥 PoCIsdecisions Userlock23/3/202317/6/2026
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaMedia (5.4)0.55%—Mark User AS Spammer Project Mark User AS Spammer6/3/202317/6/2026
A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url leads to cross site scripting. The attack can be launched remotely.…
ModificadaCrítica (9.8)0.63%—Glox Useroam Hotspot2/3/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.
ModificadaMedia (6.1)0.48%—ADD User Project ADD User27/2/202317/6/2026
The Custom Add User WordPress plugin through 2.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.5)0.66%—User Activity Project User Activity27/2/202317/6/2026
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing