Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Wpguppy ONE TO ONE User ChatAI | 14/2/2026 | 17/6/2026 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view… | |
| Modificada | Alta (8.5) | 0.19% | — | Siemens Sinec NMSSiemens User Management Component | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to… | |
| Analizada | Alta (8.1) | 0.38% | — | Tanium End-user-cx | 10/2/2026 | 17/6/2026 | Tanium addressed an arbitrary file deletion vulnerability in end-user-cx. | |
| Analizada | Media (6) | 0.20% | — | Tanium End-user Notifications | 9/2/2026 | 17/6/2026 | Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools. | |
| Aplazada | Media (4.3) | 0.14% | — | Ayecode UserswpAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53. | |
| Aplazada | Media (5.4) | 0.11% | — | Simple-membership-plugin Simple Membership WP User ImportAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1. | |
| Analizada | Ninguna (0) | 0.35% | — | Mediawiki Checkuser | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUser: from * before 1.39.14, 1.43.4, 1.44.1. | |
| Analizada | Baja (1.3) | 0.27% | — | Mediawiki Checkuser | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/GlobalContributions/GlobalContributionsPager.Php. This issue affects CheckUser: from * before 1.43.4, 1.44.1. | |
| Analizada | Ninguna (0) | 0.22% | — | Mediawiki Checkuser | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser/checkuser/checkUserHelper/buildUserElement.Js. This issue affects CheckUser: from * before 1.44.1. | |
| Aplazada | Baja (1.1) | 0.29% | — | Wikimedia CheckuserAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Services/CheckUserUserInfoCardService.Php. This issue affects CheckUser: from * before… | |
| Aplazada | Baja (1.1) | 0.36% | — | Wikimedia CheckuserAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Services/CheckUserUserInfoCardService.Php. This issue affects CheckUser: from 7cedd58781d261f110651b6af4f41d2d11ae7309. | |
| Analizada | Ninguna (0) | 0.17% | — | Mediawiki Checkuser | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/ShowIPButton.Vue, modules/ext.CheckUser.TempAccounts/SpecialBlock.Js. This issue… | |
| Aplazada | Baja (0.4) | 0.34% | — | Wikimedia CheckuserAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Api/Rest/Handler/UserInfoHandler.Php. This issue affects CheckUser: from a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4. | |
| Aplazada | Crítica (9.8) | 0.54% | 💥 PoC | User Profile BuilderAI | 2/2/2026 | 17/6/2026 | The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account | |
| Modificada | Crítica (9.8) | 0.45% | — | N3uron WEB User Interface | 29/1/2026 | 5/7/2026 | An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format | |
| Aplazada | Alta (8.8) | 0.46% | — | Webdamn User Registration Login SystemAI | 28/1/2026 | 17/6/2026 | WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel. | |
| Aplazada | Alta (8.8) | 0.33% | — | Simple User RegistrationAI | 28/1/2026 | 17/6/2026 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user… | |
| Aplazada | Alta (7.3) | 0.36% | — | Wpexperts NEW User ApproveAI | 28/1/2026 | 17/6/2026 | The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to approve or deny user accounts, retrieve… | |
| Aplazada | Media (5.3) | 0.30% | — | Solwininfotech User Activity LOGAI | 28/1/2026 | 17/6/2026 | The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off) | |
| Aplazada | Alta (7.2) | 0.24% | — | User Submitted Posts Enable Users TO Submit Posts From THE Front ENDAI | 24/1/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom fields in all versions up to, and including, 20251210 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.18% | — | Alex User CounterAI | 24/1/2026 | 17/6/2026 | The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0. This is due to missing nonce validation on the alex_user_counter_function() function. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpeverest User-registrationAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.9. | |
| Aplazada | Alta (8.8) | 0.32% | — | E-plugins Final UserAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Final UserAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Final User final-user allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Final User: from n/a through <= 1.2.5. | |
| Aplazada | Alta (8.2) | 0.36% | — | Wpeverest User RegistrationAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.6. |