Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Properfraction Profilepress | 7/7/2021 | 17/6/2026 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. . | |
| Modificada | Media (6.1) | 0.92% | — | Profilepress Loginwp | 22/8/2019 | 17/6/2026 | The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs. | |
| Modificada | Alta (8.8) | 0.67% | — | Profilepress Loginwp | 16/8/2019 | 17/6/2026 | The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF. |