Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.18% | — | Coatedmedia User Profile BuilderAI | 19/11/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (4.8) | 0.12% | — | Intel Vtune ProfilerAI | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel VTune Profiler before version 2025.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local… | |
| Aplazada | Alta (7.1) | 0.24% | — | Metagauss ProfilegridAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Reflected XSS.This issue affects ProfileGrid : from n/a through <= 5.9.5.7. | |
| Aplazada | Alta (7.1) | 0.13% | — | Ultimate Twitter Profile WidgetAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget ultimate-twitter-profile-widget allows Stored XSS.This issue affects Ultimate twitter profile widget: from n/a through <= 1.0. | |
| Aplazada | Media (6.9) | 0.22% | — | Perl PreparecompanyprofileexportjsonAI | 27/8/2025 | 17/6/2026 | In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. | |
| Aplazada | Alta (8.6) | 0.47% | — | Buddypress Xprofile Custom Image FieldAI | 20/8/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-xprofile-image-field allows Path Traversal.This issue affects BuddyPress XProfile Custom Image Field: from n/a through <= 3.0.1. | |
| Aplazada | Media (6.5) | 0.44% | — | ProfilepressAI | 16/8/2025 | 17/6/2026 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an action that does not… | |
| Aplazada | Media (6.4) | 0.20% | — | Codesigner User Profile BuilderAI | 16/8/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Alta (8.5) | 0.27% | — | Metagauss ProfilegridAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.3. | |
| Aplazada | Alta (7) | 0.24% | — | Joomla ProfilesAI | 23/7/2025 | 17/6/2026 | A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. | |
| Aplazada | Alta (8.5) | 0.37% | — | Metagauss ProfilegridAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Activity-log.com Profiler - What Slowing Down Your WPAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Profiler - What Slowing Down Your WP: from n/a through 1.0.0. | |
| Analizada | Media (6.1) | 0.30% | — | Metagauss Profilegrid | 16/7/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (10) | 2.9% | 💥 Exploit | Riverbed Steelcentral NetprofilerAIRiverbed Steelcentral NetexpressAI | 15/7/2025 | 17/6/2026 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the appliance database. This user can then… | |
| Aplazada | Media (6.5) | 0.30% | — | Aviplugins WP Register Profile With ShortcodeAI | 11/7/2025 | 17/6/2026 | The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'rp_user_data' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data from user meta… | |
| Aplazada | Media (4.3) | 0.25% | — | Metagauss ProfilegridAI | 20/6/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Retrieve Embedded Sensitive Data.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. | |
| Aplazada | Media (6.5) | 0.23% | — | Aviplugins WP Register Profile With ShortcodeAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com WP Register Profile With Shortcode wp-register-profile-with-shortcode allows Stored XSS.This issue affects WP Register Profile With Shortcode: from n/a through <= 3.6.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Wpeventmanager WP User Profile AvatarAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6. | |
| Aplazada | Media (4.9) | 0.17% | — | Metagauss ProfilegridAI | 17/6/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Server Side Request Forgery.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. | |
| Aplazada | Media (4.3) | 0.14% | — | Yougler Blogger Profile PageAI | 14/6/2025 | 17/6/2026 | The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible for unauthenticated attackers to update the plugin's settings via… | |
| Aplazada | Media (5.3) | 0.26% | — | THE Profiler What Slowing Down Your WPAI | 7/6/2025 | 17/6/2026 | The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated… | |
| Aplazada | Alta (7.1) | 0.13% | — | Jatinder PAL Singh BP Profile AS HomepageAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allows Stored XSS.This issue affects BP Profile as Homepage: from n/a through <= 1.1. | |
| Aplazada | Media (4.3) | 0.31% | — | Cozmoslabs Profile BuilderAI | 6/6/2025 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8. | |
| Aplazada | Media (6.4) | 0.29% | — | Cozmoslabs Profile BuilderAI | 3/6/2025 | 17/6/2026 | The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.5) | 0.40% | — | Metagauss ProfilegridAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.0. |