Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.65% | — | Ayecode Userswp | 7/3/2022 | 17/6/2026 | The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar. | |
| Modificada | Media (4.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 28/2/2022 | 17/6/2026 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues | |
| Modificada | Alta (7.2) | 1.5% | — | Wp-display-users Project Wp-display-users | 20/9/2021 | 17/6/2026 | The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. | |
| Modificada | Crítica (9.8) | 2.7% | — | Artixlinux Opensysusers | 25/8/2021 | 17/6/2026 | opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that. | |
| Modificada | Media (6.1) | 0.41% | — | Migrate Users Project Migrate Users | 2/8/2021 | 17/6/2026 | The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its options, allowing the issue to be exploited via a CSRF attack. | |
| Modificada | Alta (7.2) | 1.4% | — | Export Users With Meta Project Export Users With Meta | 6/7/2021 | 17/6/2026 | The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection. | |
| Modificada | Alta (8) | 1.8% | — | Codection Import AND Export Users AND Customers | 4/11/2020 | 17/6/2026 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. | |
| Modificada | Media (5.5) | 0.55% | — | Trustedcomputinggroup TrousersFedoraproject Fedora | 13/8/2020 | 17/6/2026 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack. | |
| Modificada | Alta (7.8) | 0.49% | — | Trousers Project TrousersFedoraproject Fedora | 13/8/2020 | 17/6/2026 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon). | |
| Modificada | Alta (7.8) | 0.49% | — | Trousers Project TrousersFedoraproject Fedora | 13/8/2020 | 17/6/2026 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed. | |
| Modificada | Alta (8.8) | 1.7% | — | Webtoffee Import Export Wordpress Users | 23/4/2020 | 17/6/2026 | The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV. | |
| Modificada | Media (6.1) | 1.3% | — | Export Users TO CSV Project Export Users TO CSV | 28/2/2020 | 17/6/2026 | The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection. | |
| Modificada | Alta (7.8) | 0.48% | — | Suse TrousersOpensuse Leap | 23/1/2020 | 17/6/2026 | UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory… | |
| Modificada | Crítica (9.8) | 1.4% | — | Fordnn Usersexportimport | 21/1/2020 | 17/6/2026 | The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data. | |
| Modificada | Alta (8.8) | 2.0% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. | |
| Modificada | Alta (8.8) | 1.7% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. | |
| Modificada | Alta (8.8) | 0.67% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | |
| Modificada | Media (5.4) | 0.71% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. | |
| Modificada | Alta (7.3) | 5.1% | 💥 Exploit | Webtoffee Import Export Wordpress Users | 23/8/2019 | 17/6/2026 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class. | |
| Modificada | Alta (8.8) | 0.69% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.93% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. | |
| Modificada | Alta (7.5) | 2.3% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. | |
| Modificada | Alta (8.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 14/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. |