Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.29% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based namespace verification (POST /v0/auth/http, POST /v0.1/auth/http) uses safeDialContext (internal/api/handlers/v0/auth/http.go:67-110) to refuse dialling private/internal… | |
| Analizada | Media (5.1) | 0.24% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published server.json.… | |
| Aplazada | Media (5.3) | 0.43% | 💥 PoC | User Registration MembershipAI | 14/5/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (4.3) | 0.35% | — | User Registration MembershipAI | 5/5/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | User Registration Advanced FieldsAI | 2/5/2026 | 17/6/2026 | The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest User RegistrationAI | 29/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through <= 5.1.5. | |
| Analizada | Media (5.9) | 0.21% | — | Elastic Package Registry | 28/4/2026 | 24/7/2026 | Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed. | |
| Aplazada | Baja (2) | 0.33% | — | Webkul BagistoAI | 21/4/2026 | 17/6/2026 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Webkul BagistoAI | 21/4/2026 | 17/6/2026 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Aplazada | Media (6.1) | 0.56% | 💥 Exploit | User Registration MembershipAI | 13/4/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed… | |
| Aplazada | Alta (8.8) | 0.30% | — | Phpgurukul Online Course RegistrationAI | 13/4/2026 | 17/6/2026 | In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page. | |
| Aplazada | Media (5.5) | 2.1% | 💥 PoC | Getgist ChatboxAI | 12/4/2026 | 17/6/2026 | A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.41% | — | Phpgurukul Online Course RegistrationAI | 9/4/2026 | 24/7/2026 | A security vulnerability has been detected in PHPGurukul Online Course Registration 3.1. This issue affects some unknown processing of the file /admin/check_availability.php. The manipulation of the argument regno leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and… | |
| Aplazada | Media (5.5) | 0.41% | — | Phpgurukul Online Course RegistrationAI | 8/4/2026 | 24/7/2026 | A weakness has been identified in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /check_availability.php. Executing a manipulation of the argument cid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the… | |
| Modificada | Alta (8.8) | 0.79% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 9/9/2026 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server. | |
| Modificada | Media (6.3) | 0.43% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel… | |
| Modificada | Media (6.5) | 0.40% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery… | |
| Analizada | Media (5.3) | 0.29% | — | Redhat Mirror Registry FOR RED HAT Openshift | 8/4/2026 | 25/7/2026 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation. | |
| Modificada | Media (5.5) | 0.46% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 22/9/2026 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization… | |
| Aplazada | Media (6.5) | 0.31% | — | User Registration MembershipAI | 8/4/2026 | 24/7/2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on… | |
| Aplazada | Media (5.3) | 0.29% | — | Nmerii NM Gift Registry AND Wishlist LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13. | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul User Registration & Login AND User Management SystemAI | 5/4/2026 | 24/7/2026 | A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is… | |
| Analizada | Alta (8.5) | 0.61% | — | Netgate Registry Cleaner | 4/4/2026 | 21/7/2026 | NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to… | |
| Aplazada | Media (6.5) | 0.36% | — | Genetechsolutions PIE RegisterAI | 4/4/2026 | 24/7/2026 | The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change… |