Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

648 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.37%—Themehunk Login RegistrationAI8/7/20268/7/2026
The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only…
AplazadaAlta (8.8)0.77%—DologinAI8/7/20268/7/2026
The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Mersenne Twister with `mt_srand((double) microtime() * 1000000)` — discarding the integer-seconds…
Pendiente de análisisMedia (4.8)0.31%—Uniflow Universal Login ManagerAI6/7/20266/7/2026
uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). Exploitation requires administrative privileges and may disclose configuration data…
AplazadaAlta (8.1)0.19%—Heateor Social LoginAI2/7/20262/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
AplazadaMedia (4.3)0.26%—MP Customize Login PageAI24/6/202625/6/2026
The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the enter_mpclp_login_options() function, which contains an inverted check (if wp_verify_nonce(...) { return false; }) and…
AplazadaAlta (8.2)0.37%—Codection Clean LoginAI17/6/202617/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
AplazadaCrítica (9.8)0.48%—Loginpress PROAI17/6/202617/6/2026
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
AplazadaAlta (8.7)0.48%—Syracom AG Secure Login 2FAAIAtlassian JiraAIAtlassian ConfluenceAIAtlassian BitbucketAI16/6/202621/6/2026
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings…
AplazadaMedia (4.4)0.18%—Simple Custom Login PageAI2/6/202622/7/2026
The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered…
AplazadaCrítica (9.8)0.90%—OTP Login With Phone NumberAI29/5/202621/7/2026
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The…
AplazadaAlta (7.2)0.35%—Login NO Captcha RecaptchaAI28/5/202617/6/2026
The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the…
AplazadaAlta (8.1)0.67%—Login With NearAI27/5/202617/6/2026
The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered as a `wp_ajax_nopriv` action and therefore reachable by unauthenticated users — accepts an attacker-supplied `account` POST parameter and issues a…
AplazadaCrítica (9.8)1.1%—Login With OTPAI27/5/202617/6/2026
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the…
AplazadaCrítica (9.4)0.56%💥 PoCGetgrav GravAIGetgrav LoginAI11/5/202617/6/2026
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registration is enabled and groups or access are included in the configured allowed fields…
AplazadaCrítica (9.8)2.9%💥 ExploitTemporary LoginAI1/5/202617/6/2026
The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before processing it. When the…
AplazadaCrítica (9.8)0.32%—Directorist Social LoginAI27/4/202617/6/2026
Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.
AplazadaAlta (8.8)0.52%—Login AS UserAI15/4/202617/6/2026
The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification…
AplazadaCrítica (9.8)0.47%💥 PoCPhp-mysql-user-login-systemAI10/4/202617/6/2026
PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.
AplazadaMedia (5.3)0.26%—Obadiah Super Custom LoginAI8/4/202624/7/2026
Missing Authorization vulnerability in Obadiah Super Custom Login super-custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Custom Login: from n/a through <= 1.1.
AplazadaBaja (2.1)0.32%—Phpgurukul User Registration & Login AND User Management SystemAI5/4/202624/7/2026
A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is…
AnalizadaMedia (4.3)0.20%—Budda Login Disable25/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.
AplazadaMedia (4.3)0.14%—Login RegisterAI21/3/202617/6/2026
The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.2.0. This is due to missing nonce validation on the settings page and insufficient input sanitization and output escaping on the 'login_register_login_post'…
AnalizadaAlta (8.1)0.30%—Microsoft Azure AD SSH Login Extension FOR Linux10/3/202617/6/2026
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
AplazadaCrítica (9.1)0.33%—Login With SalesforceAI5/3/202617/6/2026
The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email
AplazadaCrítica (9.8)0.73%—Miniorange ALL IN ONE Microsoft 365 Entra ID Azure AD SSO LoginAI3/3/202617/6/2026
The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.
Orbitaley — Vulnerabilidades