Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.23% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When… | |
| Analizada | Crítica (9.3) | 0.39% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from… | |
| Aplazada | Alta (7.2) | 0.31% | — | Cleantalk Login Security Firewall Malware RemovalAI | 9/12/2025 | 17/6/2026 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.37% | — | Wpmet WP Social Login AND Register Social CounterAI | 5/12/2025 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback… | |
| Aplazada | Media (4.3) | 0.15% | — | Nextend Social Login AND RegisterAI | 28/11/2025 | 30/9/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login… | |
| Analizada | Crítica (9.8) | 0.49% | — | 2dogz Blogin | 20/11/2025 | 17/6/2026 | An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful… | |
| Aplazada | Media (4.3) | 0.20% | — | MO JWT Generate NEW API KEY WP Login AND Register Using JWTAI | 19/11/2025 | 17/6/2026 | The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mo_jwt_generate_new_api_key' function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (4.3) | 0.12% | — | WP Custom Admin Login Page LogoAI | 11/11/2025 | 17/6/2026 | The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This is due to missing or incorrect nonce validation on the wpclpl_save functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings… | |
| Aplazada | Media (5.3) | 0.36% | — | Wpexperts ALL IN ONE LoginAI | 6/11/2025 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spoofing.This issue affects All In One Login: from n/a through <= 2.0.8. | |
| Aplazada | Alta (7.1) | 0.30% | — | Cynob IT Consultancy Auto Login After RegistrationAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy Auto Login After Registration auto-login-after-registration allows Reflected XSS.This issue affects Auto Login After Registration: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.30% | — | Calvaweb Password Only LoginAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password only login password-only-login allows Reflected XSS.This issue affects Password only login: from n/a through <= 0.2. | |
| Aplazada | Media (4.3) | 0.27% | — | External LoginAI | 15/10/2025 | 17/6/2026 | The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX action lacking capability checks or nonce validation. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Alta (7.5) | 0.40% | 💥 PoC | External LoginAI | 15/10/2025 | 17/6/2026 | The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, and including, 1.11.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.30% | — | Yourmembership YM SSO LoginAI | 15/10/2025 | 17/6/2026 | The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to read the profile data… | |
| Aplazada | Crítica (9.8) | 0.79% | 💥 PoC | Ownid Passwordless LoginAI | 15/10/2025 | 17/6/2026 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.29% | — | Quick Social LoginAI | 15/10/2025 | 17/6/2026 | The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' shortcode in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.35% | — | Authenticator Login Project Authenticator Login | 10/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8. | |
| Analizada | Media (4.8) | 0.26% | — | Phpgurukul User Registration & Login AND User Management System | 30/9/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters. | |
| Aplazada | Media (6.5) | 0.31% | — | Jeff Farthing Theme MY LoginAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theme My Login: from n/a through <= 7.1.12. | |
| Aplazada | Media (5.3) | 0.29% | — | Greg Winiarski Custom Login URLAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Greg Winiarski Custom Login URL custom-login-url allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login URL: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Nicu Micle Simple JWT LoginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicu Micle Simple JWT Login simple-jwt-login allows Stored XSS.This issue affects Simple JWT Login: from n/a through <= 3.6.4. | |
| Aplazada | Media (5.9) | 0.30% | — | Webvitaly Login-logoutAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Login-Logout login-logout allows Stored XSS.This issue affects Login-Logout: from n/a through <= 3.8. | |
| Aplazada | Media (5.9) | 0.22% | — | Brijeshk89 Ip-based-loginAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login ip-based-login allows Stored XSS.This issue affects IP Based Login: from n/a through <= 2.4.3. | |
| Aplazada | Media (4.3) | 0.13% | — | Custom Login AND Signup WidgetAI | 20/9/2025 | 17/6/2026 | The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in the /frndzk_adminclsw.php file. This makes it possible for unauthenticated attackers to change the email and username… | |
| Aplazada | Alta (7.7) | 0.32% | — | OneloginAI | 14/9/2025 | 17/6/2026 | In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created), |