Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.14% | — | Intel Oneapi Base ToolkitIntel Vtune Profiler | 14/8/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Crítica (9.8) | 0.80% | — | Cozmoslabs Profile Builder | 31/7/2024 | 17/6/2026 | it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process. | |
| Analizada | Crítica (9.1) | 29% | 💥 Exploit | Cozmoslabs Profile Builder | 29/7/2024 | 17/6/2026 | The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP. | |
| Modificada | Alta (8.8) | 0.77% | — | Metagauss Profilegrid | 10/7/2024 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.35% | — | Metagauss Profilegrid | 10/7/2024 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.41% | — | Cozmoslabs User Profile Picture | 21/6/2024 | 17/6/2026 | The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access… | |
| Modificada | Media (6.3) | 0.30% | — | Metagauss Profilegrid | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6. | |
| Modificada | Media (4.3) | 0.35% | — | Metagauss Profilegrid | 5/6/2024 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.29% | — | Properfraction Profilepress | 23/5/2024 | 17/6/2026 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.47% | — | Metagauss Profilegrid | 17/5/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2. | |
| Aplazada | Media (5.3) | 0.22% | — | Cozmoslabs Profile BuilderAI | 17/5/2024 | 17/6/2026 | Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Glowlogix WP Frontend ProfileAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1. | |
| Analizada | Alta (8.6) | 1.3% | 💥 Exploit | Properfraction Profilepress | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1. | |
| Analizada | Alta (7.8) | 0.18% | — | Intel Vtune Profiler | 16/5/2024 | 17/6/2026 | Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 0.45% | — | Metagauss Profilegrid | 2/5/2024 | 17/6/2026 | The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.38% | — | Properfraction Profilepress | 2/5/2024 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escaping.… | |
| Analizada | Media (4.3) | 0.49% | — | Redhat Trusted Profile Analyzer | 25/4/2024 | 17/6/2026 | A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed. | |
| Modificada | Alta (8.8) | 0.45% | — | Metagauss Profilegrid | 24/4/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. | |
| Modificada | Alta (8.8) | 0.45% | — | Metagauss Profilegrid | 24/4/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. | |
| Analizada | Media (5.4) | 0.42% | — | Wpeventsmanager User Profile Avatar | 15/4/2024 | 17/6/2026 | The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.23% | — | Metagauss Profilegrid | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | |
| Modificada | Media (5.4) | 0.43% | — | Properfraction Profilepress | 10/4/2024 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'reg-single-checkbox' shortcode in all versions up to, and including, 4.15.5 due to insufficient input… | |
| Modificada | Alta (7.1) | 0.38% | — | Metagauss Profilegrid | 7/4/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6. | |
| Modificada | Media (6.5) | 0.46% | — | Metagauss Profilegrid | 29/3/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2. | |
| Modificada | Alta (8.8) | 32% | — | Metagauss Profilegrid | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. |