Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | Heateor Login Social LoginAI | 10/9/2025 | 17/6/2026 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.13% | — | Samer Bechara Ultimate Ajax LoginAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Samer Bechara Ultimate AJAX Login ultimate-ajax-login allows Reflected XSS.This issue affects Ultimate AJAX Login: from n/a through <= 1.2.1. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Idehweb Login With Phone NumberAI | 31/8/2025 | 6/10/2026 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93. | |
| Analizada | Crítica (9.8) | 0.41% | — | Vishnusivadas Login-signup | 22/8/2025 | 17/6/2026 | The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build queries by directly concatenating user input and unvalidated table names without using prepared statements. While a prepareData() function… | |
| Aplazada | Alta (8.1) | 0.40% | — | Simplerealtytheme Simple Login LOGAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Max Chirkov Simple Login Log allows Object Injection. This issue affects Simple Login Log: from n/a through 1.1.3. | |
| Analizada | Crítica (9.8) | 0.52% | — | Authenticator Login Project Authenticator Login | 15/8/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4. | |
| Aplazada | Alta (8.1) | 0.64% | — | OTP Login With Phone Number OTP VerificationAI | 15/8/2025 | 17/6/2026 | The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP… | |
| Aplazada | Media (6.9) | 0.40% | — | Onelogin Ruby-samlAI | 30/7/2025 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Melapress Login SecurityAI | 26/7/2025 | 17/6/2026 | The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication… | |
| Analizada | Baja (2.1) | 0.44% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Login and User Management System 3.3. It has been declared as critical. This vulnerability affects unknown code of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3. It has been classified as critical. This affects an unknown part of the file /admin/lastthirtyays-reg-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.41% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/lastsevendays-reg-users.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The… | |
| Aplazada | Alta (8.1) | 0.51% | — | Orion Login With SMSAI | 22/7/2025 | 17/6/2026 | The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() function not utilizing a strong enough OTP value, exposing the hash needed to generate the OTP value, and no restrictions on the number of… | |
| Analizada | Crítica (9.8) | 0.46% | — | Mqanneh Mail Login | 21/7/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0. | |
| Aplazada | Media (4) | 0.24% | — | Oneidentity OneloginAI | 19/7/2025 | 17/6/2026 | In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Loginpress PROAI | 18/7/2025 | 17/6/2026 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site,… | |
| Analizada | Baja (2.1) | 0.42% | — | Phpgurukul User Registration & Login AND User Management System | 13/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.5) | 0.52% | — | Phpgurukul User Registration & Login AND User Management System | 13/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.35% | — | Doccheck LoginAI | 4/7/2025 | 17/6/2026 | The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin redirecting a user to login on a password protected post after the page has loaded. This makes it possible for unauthenticated attackers to read posts they should not… | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Analizada | Media (6.1) | 0.24% | — | Hellomohsinkhan WP Front-end Login AND Register | 2/7/2025 | 17/6/2026 | The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9) | 0.53% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. These logs may contain… | |
| Aplazada | Crítica (10) | 0.61% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin… | |
| Aplazada | Media (5.7) | 0.16% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing… | |
| Aplazada | Crítica (9.1) | 2.4% | 💥 Exploit | Bitto.kazi Custom Login AND Signup WidgetAI | 1/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0. |