Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices… | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted. | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted. | |
| Analizada | Alta (7.1) | 0.38% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be… | |
| Analizada | Alta (7.1) | 0.38% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may… | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door… | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices… | |
| Analizada | Alta (7.1) | 0.40% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices… | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted. | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted. | |
| Aplazada | Alta (8.8) | 0.72% | — | Ultimatemember Ultimate MemberAI | 24/6/2026 | 25/6/2026 | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() that allows any post to be used as a member directory by computing… | |
| Aplazada | Media (5.3) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 18/6/2026 | 18/6/2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Tipsandtricks-hq WP EmemberAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Wishlistmember Wishlist MemberAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | |
| Aplazada | Media (4.3) | 0.26% | — | Wishlistmember Wishlist MemberAI | 17/6/2026 | 17/6/2026 | Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paid Member SubscriptionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions. | |
| Analizada | Media (6.9) | 0.10% | — | Samsung Members | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege. | |
| Aplazada | Media (5.3) | 0.33% | — | Tips AND Tricks HQ WP EmemberAI | 4/6/2026 | 22/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2. | |
| Aplazada | Crítica (9.8) | 0.48% | 💥 PoC | Armember PremiumAI | 2/6/2026 | 21/7/2026 | The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the… | |
| Aplazada | Media (6.5) | 0.38% | — | Armember PremiumAI | 2/6/2026 | 21/7/2026 | The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is concatenated directly into the ORDER BY… | |
| Aplazada | Alta (7.5) | 1.6% | 💥 Exploit | ArmemberAI | 2/6/2026 | 21/7/2026 | The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient… | |
| Aplazada | Alta (7.3) | 0.30% | — | Wclovers Wcfm MembershipAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10. | |
| Aplazada | Alta (8.8) | 0.44% | — | Wishlistmember Wishlist MemberAI | 23/5/2026 | 23/7/2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and… |