Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.51%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel6/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.
ModificadaMedia (6.1)0.41%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel29/6/202317/6/2026
A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php.
ModificadaMedia (5.4)0.34%—Techtime User Management26/6/202317/6/2026
The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.
ModificadaMedia (6.1)0.36%—User Registration & Login AND User Management System Project User Registration & Login AND User Management System21/6/202317/6/2026
User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
ModificadaMedia (4.3)0.48%—Oracle User Management18/4/202317/6/2026
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful…
ModificadaMedia (5.4)0.57%💥 PoCUser Registration & User Management System Project User Registration & User Management System5/12/202217/6/2026
Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages.
ModificadaMedia (6.5)2.3%—User-meta User Meta User Profile Builder AND User Management8/6/202217/6/2026
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
ModificadaMedia (4.8)0.59%—User-meta User Meta User Profile Builder AND User Management30/5/202217/6/2026
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaAlta (7.5)72%💥 ExploitOracle E-business SuiteOracle User Management20/5/202217/6/2026
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized…
ModificadaMedia (6.5)0.40%—User Management System IN PHP Stored Procedure Project User Management System IN PHP Stored Procedure16/12/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.
ModificadaMedia (6.1)0.74%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel22/10/202117/6/2026
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
ModificadaMedia (4.3)0.91%—Oracle Enterprise Data QualityOracle Retail Invoice MatchingOracle User Management20/1/202117/6/2026
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management.…
ModificadaAlta (8.8)0.65%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel26/12/202017/6/2026
A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.
ModificadaMedia (4.8)1.0%—Phpgurukul User Registration & Login AND User Management System18/11/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.
ModificadaCrítica (9.8)4.1%—Phpgurukul User Registration & Login AND User Management System16/11/202017/6/2026
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
ModificadaMedia (5.4)1.6%💥 ExploitArdawan User Management19/10/201817/6/2026
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.
ModificadaMedia (6.5)2.0%—Oracle User Management17/10/201817/6/2026
Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Reports). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User…
ModificadaAlta (8.8)3.5%—Jigowatt PHP Login & User Management29/5/201817/6/2026
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile avatar field. This results in arbitrary code execution by…
ModificadaMedia (5.4)0.89%—Oracle User Management18/1/201817/6/2026
Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Proxy User Delegation). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaAlta (7.5)1.1%—Deadlock User Management System13/1/200716/6/2026
SQL injection vulnerability in Deadlock User Management System (phpdeadlock) 0.64 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.