Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.23% | — | File Sharing Download Manager User Private FilesAI | 16/6/2026 | 17/6/2026 | The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Wpusermanager WP User ManagerAI | 15/6/2026 | 17/6/2026 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Unauthenticated Broken Access Control IN User RegistrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions. | |
| Aplazada | Media (4.7) | 0.24% | — | Open User MAP PROAI | 11/6/2026 | 23/7/2026 | The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (4.3) | 0.26% | — | Weplugins User FrontendAI | 9/6/2026 | 23/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Alta (7.5) | 2.7% | 💥 Exploit | Wpusermanager WP User ManagerAI | 6/6/2026 | 23/7/2026 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server,… | |
| Aplazada | Media (4.3) | 0.19% | — | Frontend User NotesAI | 6/6/2026 | 23/7/2026 | The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it possible for unauthenticated attackers to trick a logged-in user into visiting… | |
| Aplazada | Media (4.3) | 0.20% | — | Remove Meta Boxes PER User RoleAI | 2/6/2026 | 22/7/2026 | The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset… | |
| Analizada | Alta (8.8) | 0.36% | — | Nextcloud User Oidc | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0. | |
| Analizada | Media (6.1) | 0.32% | — | Nextcloud User Oidc | 1/6/2026 | 20/7/2026 | Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2. | |
| Aplazada | Alta (8.1) | 0.55% | 💥 PoC | Nextcloud User OidcAI | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0,… | |
| Aplazada | Alta (7.5) | 0.42% | — | Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI | 1/6/2026 | 22/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a… | |
| Aplazada | Media (5.3) | 0.39% | — | Wpeverest User RegistrationAI | 28/5/2026 | 17/6/2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is due to missing ownership validation on a… | |
| Pendiente de análisis | Media (5.6) | 0.25% | — | Checkpoint DLPAICheckpoint Usercheck WEB PortalAI | 26/5/2026 | 24/7/2026 | When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as… | |
| Aplazada | Crítica (9.3) | 0.43% | — | UserspiceAI | 23/5/2026 | 6/10/2026 | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the… | |
| Aplazada | Media (5.1) | 0.15% | — | UserspiceAI | 23/5/2026 | 6/10/2026 | userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log… | |
| Aplazada | Media (6.4) | 0.32% | — | Faces OF UsersAI | 20/5/2026 | 24/7/2026 | The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions up to, and including, 0.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.70% | — | Huggingface Diffusers | 14/5/2026 | 17/6/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.py performs string… | |
| Modificada | Alta (8.8) | 0.89% | — | Huggingface Diffusers | 14/5/2026 | 28/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing… | |
| Aplazada | Media (5.3) | 0.43% | 💥 PoC | User Registration MembershipAI | 14/5/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or… | |
| Aplazada | Media (6.5) | 0.41% | — | Libwww-perl LWP UseragentAI | 12/5/2026 | 17/6/2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the… | |
| Analizada | Media (4.8) | 0.38% | — | Mediawiki Checkuser | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2. | |
| Aplazada | Alta (8.8) | 1.3% | — | Wedevs User FrontendAI | 8/5/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form… | |
| Aplazada | Media (4.3) | 0.35% | — | User Registration MembershipAI | 5/5/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (8.8) | 0.72% | — | Codection Import AND Export Users AND CustomersAI | 2/5/2026 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g.,… |