Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.82% | — | Multi User Project Multi User | 25/9/2020 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL. | |
| Analizada | Media (5.5) | 0.41% | — | Libuser Project LibuserDebian LinuxFedoraproject FedoraRedhat Enterprise Linux | 25/11/2019 | 16/6/2026 | libuser has information disclosure when moving user's home directory | |
| Modificada | Media (6.3) | 0.28% | — | Libuser Project LibuserFedoraproject FedoraRedhat Enterprise Linux | 25/11/2019 | 16/6/2026 | libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. | |
| Modificada | Media (6.1) | 83% | 💥 Exploit | Instagram-php-api Project Instagram-php-apiUserproplugin User PRO | 4/9/2019 | 17/6/2026 | cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 2.4% | 💥 Exploit | User Project User | 25/4/2018 | 17/6/2026 | An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field. | |
| Modificada | Media (4.8) | 0.62% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | |
| Modificada | Alta (8.8) | 0.67% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin. | |
| Analizada | Alta (7.4) | 8.4% | ⚠ Explotación activa💥 Exploit | Redhat Enterprise LinuxOpensuseLibuser Project Libuser | 11/8/2015 | 2/10/2026 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to… | |
| Modificada | Media (4.3) | 1.9% | — | Zfcuser Project Zfcuser | 15/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in user/login.phtml in ZF-Commons ZfcUser before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter. |