Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—Properfraction Profilepress7/7/202117/6/2026
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .
ModificadaAlta (8.8)4.1%💥 ExploitProperfraction Profilepress7/7/202117/6/2026
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .
ModificadaCrítica (9.8)69%💥 ExploitProperfraction Profilepress7/7/202117/6/2026
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .
ModificadaMedia (6.1)0.92%—Profilepress Loginwp22/8/201917/6/2026
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
ModificadaAlta (8.8)0.67%—Profilepress Loginwp16/8/201917/6/2026
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
Orbitaley — Vulnerabilidades