Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.75% | — | Wpeverest User Registration | 12/12/2022 | 17/6/2026 | The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example. | |
| Modificada | Media (5.4) | 0.57% | 💥 PoC | User Registration & User Management System Project User Registration & User Management System | 5/12/2022 | 17/6/2026 | Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages. | |
| Modificada | Crítica (9.8) | 1.3% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 2/6/2022 | 17/6/2026 | EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.74% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 22/10/2021 | 17/6/2026 | Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields. | |
| Modificada | Media (5.4) | 0.62% | — | Wpeverest User Registration | 4/10/2021 | 17/6/2026 | The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their… | |
| Modificada | Crítica (9.8) | 2.5% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 26/1/2021 | 17/6/2026 | EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution. | |
| Modificada | Media (5.4) | 0.60% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers. | |
| Modificada | Media (6.1) | 0.81% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the… | |
| Modificada | Alta (7.5) | 1.1% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page. | |
| Modificada | Alta (8.8) | 0.65% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 26/12/2020 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1. | |
| Modificada | Media (6.1) | 0.97% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 23/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0. | |
| Modificada | Alta (8) | 0.57% | — | Egavilanmedia User Registration & Login System With Admin Panel | 21/12/2020 | 9/7/2026 | EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account. | |
| Modificada | Media (4.8) | 1.0% | — | Phpgurukul User Registration & Login AND User Management System | 18/11/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1. | |
| Modificada | Crítica (9.8) | 4.1% | — | Phpgurukul User Registration & Login AND User Management System | 16/11/2020 | 17/6/2026 | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Phpbb ACP User Registration Module | 18/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+1 | 21/4/2006 | 16/6/2026 | Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell… |