Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.96% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 12/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. | |
| Modificada | Media (5.7) | 0.68% | — | Codection Import Users From CSV With Meta | 8/8/2019 | 17/6/2026 | The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF. | |
| Modificada | Media (6.1) | 0.78% | — | Codection Import Users From CSV With Meta | 12/12/2018 | 17/6/2026 | The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. | |
| Modificada | Alta (8.6) | 1.5% | — | Export Users TO CSV Project Export Users TO CSV | 28/8/2018 | 17/6/2026 | The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. | |
| Modificada | Alta (8.8) | 0.58% | — | Userscape Helpspot | 19/2/2018 | 17/6/2026 | An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account. | |
| Modificada | Media (6.1) | 0.89% | — | Userscape Helpspot | 19/2/2018 | 17/6/2026 | An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when the return link is clicked. | |
| Modificada | Media (5.5) | 0.38% | — | Criu Checkpoint/restore IN UserspaceOpensuse | 7/6/2016 | 17/6/2026 | The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access. | |
| Modificada | Alta (7.8) | 0.39% | — | OpensuseCriu Checkpoint/restore IN Userspace | 7/6/2016 | 17/6/2026 | The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path. | |
| Modificada | Alta (7.5) | 2.3% | — | Usersultra | 9/6/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote parameter in a rating_vote (wp_ajax_nopriv_rating_vote) action to wp-admin/admin-ajax.php. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Trustedcomputinggroup Trousers | 26/11/2012 | 16/6/2026 | tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003. | |
| Modificada | Media (4.3) | 1.2% | — | Ricky Morse Excluded Users | 31/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Excluded Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) user name or (2) email address. | |
| Modificada | Baja (2.1) | 1.5% | — | PuppetPuppet EnterprisePuppetlabs PuppetPuppetlabs Puppet Enterprise Users | 29/5/2012 | 16/6/2026 | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST… | |
| Modificada | Baja (3.3) | 0.35% | — | PuppetPuppet EnterprisePuppetlabs PuppetPuppetlabs Puppet Enterprise Users | 29/5/2012 | 16/6/2026 | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink… | |
| Modificada | Media (4.4) | 0.37% | — | PuppetPuppetlabs PuppetPuppet EnterprisePuppetlabs Puppet Enterprise Users | 29/5/2012 | 16/6/2026 | Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login. | |
| Modificada | Media (6.9) | 0.38% | — | PuppetPuppetlabs PuppetPuppet EnterprisePuppetlabs Puppet Enterprise Users | 29/5/2012 | 16/6/2026 | The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the… | |
| Modificada | Media (5) | 1.2% | — | Typo3 Beuserswitch | 14/2/2012 | 16/6/2026 | Unspecified vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Typo3 Beuserswitch | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Wordpress-users | 2/12/2011 | 16/6/2026 | SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the uid parameter to index.php. | |
| Modificada | Baja (2.6) | 2.5% | 💥 PoC | PuppetPuppetlabs PuppetPuppet EnterprisePuppetlabs Puppet Enterprise Users | 27/10/2011 | 16/6/2026 | Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via… | |
| Modificada | Media (5) | 14% | 💥 Exploit | Joomlamo COM Userstatus | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Frontend Users View | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Sloughflash Sf-users | 4/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element. |