Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 19% | — | Codeastro Membership Management System | 28/2/2024 | 17/6/2026 | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component. | |
| Analizada | Media (6.1) | 0.58% | — | Codeastro Membership Management System | 28/2/2024 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component. | |
| Analizada | Crítica (9.1) | 0.67% | — | Codeastro Membership Management System | 28/2/2024 | 17/6/2026 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component. | |
| Analizada | Alta (8.8) | 0.79% | — | Codeastro Membership Management System | 28/2/2024 | 17/6/2026 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component. | |
| Analizada | Media (5.3) | 0.47% | — | Codeastro Membership Management System | 27/2/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /get_membership_amount.php. The manipulation of the argument membershipTypeId leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Alta (7.2) | 0.67% | — | Codeastro Membership Management System | 23/2/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add Members Tab. The manipulation of the argument Member Photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 0.67% | — | Codeastro Membership Management System | 23/2/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /uploads/ of the component Logo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.3) | 0.38% | — | Discourse Group Membership IP Blocks | 1/2/2024 | 17/6/2026 | discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret. | |
| Modificada | Media (5.3) | 0.95% | 💥 PoC | Strangerstudios Paid Memberships PRO | 25/1/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible… | |
| Modificada | Media (6.1) | 0.28% | — | Simple-membership-plugin Simple Membership | 24/1/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1. | |
| Modificada | Crítica (9.8) | 1.00% | — | Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+11 | 19/1/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long… | |
| Modificada | Media (6.1) | 0.38% | — | Simple-membership-plugin Simple Membership | 11/1/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (5.3) | 0.51% | — | Strangerstudios Paid Memberships PRO | 11/1/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up… | |
| Modificada | Media (5.4) | 0.61% | — | Carmelogarcia Intern Membership Management System | 28/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /user_registration/ of the component User Registration. The manipulation of the argument userName/firstName/lastName/userEmail with the input… | |
| Modificada | Crítica (9.8) | 0.72% | — | Carmelogarcia Intern Membership Management System | 28/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Intern Membership Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user_registration/ of the component User Registration. The manipulation of the argument userName leads to sql injection. The exploit has been… | |
| Modificada | Media (6.1) | 0.46% | — | Simple-membership-plugin Simple Membership | 19/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8. | |
| Modificada | Alta (8.8) | 51% | — | Strangerstudios Paid Memberships PRO | 18/11/2023 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or… | |
| Modificada | Media (4.3) | 0.39% | — | Strangerstudios Paid Memberships PRO | 20/10/2023 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they… | |
| Modificada | Crítica (9.8) | 0.82% | — | Razormist Simple Membership System | 29/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.61% | — | Razormist Simple Membership System | 17/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.61% | — | Razormist Simple Membership System | 9/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been rated as critical. This issue affects some unknown processing of the file delete_member.php. The manipulation of the argument mem_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Razormist Simple Membership System | 9/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.60% | — | Razormist Simple Membership System | 8/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been classified as critical. This affects an unknown part of the file club_edit_query.php. The manipulation of the argument club_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.1) | 0.57% | — | Simple-membership-plugin Simple Membership | 6/9/2023 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could inject arbitrary web scripts into pages… | |
| Modificada | Media (4.8) | 0.36% | — | Minorange Wordpress Yourmembership Single Sign-on | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Login plugin <= 1.1.3 versions. |