Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.14%—Intel Oneapi Base ToolkitIntel Vtune Profiler14/8/202417/6/2026
Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (9.8)0.80%—Cozmoslabs Profile Builder31/7/202417/6/2026
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
AnalizadaCrítica (9.1)29%💥 ExploitCozmoslabs Profile Builder29/7/202417/6/2026
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
ModificadaAlta (8.8)0.77%—Metagauss Profilegrid10/7/202417/6/2026
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.3)0.35%—Metagauss Profilegrid10/7/202417/6/2026
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.3)0.41%—Cozmoslabs User Profile Picture21/6/202417/6/2026
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access…
ModificadaMedia (6.3)0.30%—Metagauss Profilegrid12/6/202417/6/2026
Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.
ModificadaMedia (4.3)0.35%—Metagauss Profilegrid5/6/202417/6/2026
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6. This makes it possible for authenticated…
ModificadaMedia (5.4)0.29%—Properfraction Profilepress23/5/202417/6/2026
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.47%—Metagauss Profilegrid17/5/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.
AplazadaMedia (5.3)0.22%—Cozmoslabs Profile BuilderAI17/5/202417/6/2026
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.
AplazadaCrítica (9.8)0.54%—Glowlogix WP Frontend ProfileAI17/5/202417/6/2026
Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.
AnalizadaAlta (8.6)1.3%💥 ExploitProperfraction Profilepress17/5/202417/6/2026
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
AnalizadaAlta (7.8)0.18%—Intel Vtune Profiler16/5/202417/6/2026
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.3)0.45%—Metagauss Profilegrid2/5/202417/6/2026
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.38%—Properfraction Profilepress2/5/202417/6/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escaping.…
AnalizadaMedia (4.3)0.49%—Redhat Trusted Profile Analyzer25/4/202417/6/2026
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
ModificadaAlta (8.8)0.45%—Metagauss Profilegrid24/4/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
ModificadaAlta (8.8)0.45%—Metagauss Profilegrid24/4/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
AnalizadaMedia (5.4)0.42%—Wpeventsmanager User Profile Avatar15/4/202417/6/2026
The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)0.23%—Metagauss Profilegrid12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
ModificadaMedia (5.4)0.43%—Properfraction Profilepress10/4/202417/6/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'reg-single-checkbox' shortcode in all versions up to, and including, 4.15.5 due to insufficient input…
ModificadaAlta (7.1)0.38%—Metagauss Profilegrid7/4/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.
ModificadaMedia (6.5)0.46%—Metagauss Profilegrid29/3/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.
ModificadaAlta (8.8)32%—Metagauss Profilegrid29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
Orbitaley — Vulnerabilidades