Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Metagauss RegistrationmagicAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 6.0.7.6. | |
| Aplazada | Alta (8.1) | 0.37% | 💥 PoC | Wpeverest User RegistrationAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9. | |
| Aplazada | Alta (8.1) | 0.38% | — | Metagauss RegistrationmagicAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1. | |
| Aplazada | Media (5.4) | 0.30% | — | User Registration MembershipAI | 24/3/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead… | |
| Aplazada | Media (4.3) | 0.14% | — | Login RegisterAI | 21/3/2026 | 17/6/2026 | The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.2.0. This is due to missing nonce validation on the settings page and insufficient input sanitization and output escaping on the 'login_register_login_post'… | |
| Aplazada | Media (5.4) | 0.29% | — | Metagauss RegistrationmagicAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 6.0.7.6. | |
| Analizada | Media (5.4) | 0.16% | — | Redhat QuayRedhat Mirror Registry | 12/3/2026 | 17/6/2026 | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing… | |
| Analizada | Alta (7.7) | 0.32% | — | Zotregistry ZOT | 10/3/2026 | 17/6/2026 | zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zot’s dist-spec authorization middleware infers the required action for PUT /v2/{name}/manifests/{reference} as create by default, and only switches to update when the tag already exists… | |
| Analizada | Alta (8.1) | 0.57% | — | Internet Routing Registry Daemon Project Internet Routing Registry Daemon | 6/3/2026 | 17/6/2026 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex Global LogisticsAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Global Logistics globallogistics allows PHP Local File Inclusion.This issue affects Global Logistics: from n/a through <= 3.20. | |
| Modificada | Alta (7.2) | 0.44% | — | Oretnom23 Simple Logistic HUB Parcel's Management System | 3/3/2026 | 17/6/2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php. | |
| Analizada | Baja (2.7) | 0.34% | — | Oretnom23 Simple Logistic HUB Parcel's Management System | 3/3/2026 | 17/6/2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php. | |
| Aplazada | Crítica (9.8) | 28% | 💥 Exploit | User Registration MembershipAI | 3/3/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role… | |
| Aplazada | Media (5.3) | 0.19% | — | User Registration AND MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes… | |
| Aplazada | Alta (8.1) | 0.36% | — | User Registration MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has… | |
| Aplazada | Media (5.3) | 0.23% | — | Metagauss RegistrationmagicAI | 18/2/2026 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' function in all versions up to, and including, 6.0.6.9. This is due to the plugin… | |
| Aplazada | Media (4.3) | 0.22% | — | Metagauss RegistrationmagicAI | 16/2/2026 | 17/6/2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site. | |
| Aplazada | Media (4.3) | 0.18% | — | Metagauss RegistrationmagicAI | 13/2/2026 | 17/6/2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above. | |
| Aplazada | Alta (8.8) | 0.35% | 💥 PoC | JAY Login RegisterAI | 8/2/2026 | 17/6/2026 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_panel_ajax_update_profile' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.46% | — | JAY Login RegisterAI | 8/2/2026 | 17/6/2026 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_create_final_user' function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.46% | — | Webdamn User Registration Login SystemAI | 28/1/2026 | 17/6/2026 | WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel. | |
| Aplazada | Alta (8.8) | 0.33% | — | Simple User RegistrationAI | 28/1/2026 | 17/6/2026 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user… | |
| Aplazada | Media (5.3) | 0.26% | — | Metagauss RegistrationmagicAI | 28/1/2026 | 17/6/2026 | The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings,… | |
| Aplazada | Alta (8.5) | 0.18% | — | Acer Global Registration ServiceAI | 27/1/2026 | 17/6/2026 | Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with… | |
| Aplazada | Media (5.1) | 0.44% | — | Dormakaba Registration Units 9002AI | 26/1/2026 | 17/6/2026 | The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can use the interface to exfiltrate PINs. As the devices are explicitly built as Plug-and-Play to be easily replaced, an attacker is easily… |