Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices…
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
AnalizadaAlta (7.1)0.38%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be…
AnalizadaAlta (7.1)0.38%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may…
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door…
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices…
AnalizadaAlta (7.1)0.40%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices…
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
AnalizadaAlta (7.1)0.44%—Silabs Emberznet25/6/202625/6/2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
AplazadaAlta (8.8)0.72%—Ultimatemember Ultimate MemberAI24/6/202625/6/2026
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() that allows any post to be used as a member directory by computing…
AplazadaMedia (5.3)0.35%—Simple-membership-plugin Simple MembershipAI18/6/202618/6/2026
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by…
AplazadaCrítica (9.3)0.40%—Tipsandtricks-hq WP EmemberAI17/6/202617/6/2026
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
AplazadaCrítica (9.9)0.48%—Wishlistmember Wishlist MemberAI17/6/202617/6/2026
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
AplazadaMedia (4.3)0.26%—Wishlistmember Wishlist MemberAI17/6/202617/6/2026
Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
AplazadaMedia (6.5)0.22%—Simple-membership-plugin Simple MembershipAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.
AplazadaAlta (7.1)0.25%—Paid Member SubscriptionsAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
AplazadaAlta (7.5)0.35%—Simple-membership-plugin Simple MembershipAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
AnalizadaMedia (6.9)0.10%—Samsung Members5/6/202630/6/2026
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
AplazadaMedia (5.3)0.33%—Tips AND Tricks HQ WP EmemberAI4/6/202622/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.
AplazadaCrítica (9.8)0.48%💥 PoCArmember PremiumAI2/6/202621/7/2026
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the…
AplazadaMedia (6.5)0.38%—Armember PremiumAI2/6/202621/7/2026
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is concatenated directly into the ORDER BY…
AplazadaAlta (7.5)1.6%💥 ExploitArmemberAI2/6/202621/7/2026
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient…
AplazadaAlta (7.3)0.30%—Wclovers Wcfm MembershipAI27/5/202617/6/2026
Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.
AplazadaAlta (8.8)0.44%—Wishlistmember Wishlist MemberAI23/5/202623/7/2026
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
Orbitaley — Vulnerabilidades