Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.92%—Profilepress WP User AvatarAI31/8/20268/9/2026
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a…
AplazadaAlta (7.5)0.66%—Onedesigns ONE User AvatarAI28/8/202628/8/2026
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in wp_handle_upload() called without a MIME allow-list, with…
AplazadaMedia (6.5)0.33%—WP Social AvatarAI13/8/202614/8/2026
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
AplazadaMedia (4.3)0.29%—Matteo Manna Simple User AvatarAI29/6/20268/7/2026
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
AnalizadaMedia (5.1)0.24%—Avatar Uploader Project Avatar Uploader10/5/202624/7/2026
Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary…
AplazadaMedia (5.3)0.31%—Paul Bearne Author Avatars List BlockAI8/4/202624/7/2026
Missing Authorization vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Author Avatars List/Block: from n/a through <= 2.1.25.
AplazadaMedia (6.5)0.16%—Saad Iqbal User Avatar ReloadedAI16/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Avatar - Reloaded user-avatar-reloaded allows Stored XSS.This issue affects User Avatar - Reloaded: from n/a through <= 1.2.2.
AplazadaMedia (6.5)0.21%—WpavatarAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 文派翻译(WP Chinese Translation) WPAvatar wpavatar allows Stored XSS.This issue affects WPAvatar: from n/a through <= 1.9.4.
AplazadaMedia (4.3)0.26%—10up Simple Local AvatarsAI12/8/202517/6/2026
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar…
AplazadaMedia (4.3)0.28%—Wpeventmanager WP User Profile AvatarAI20/6/202517/6/2026
Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6.
AplazadaAlta (8.1)1.0%—Jenkins AvatarAI18/4/202517/6/2026
The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can…
AplazadaMedia (4.3)0.34%—Jenkins AvatarAI17/4/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Avatar: from n/a through <= 0.1.4.
ModificadaAlta (8.8)0.19%—Venugopal Comment Date AND Gravatar Remover11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0.
AplazadaAlta (7.1)0.20%—Cybio GravatarlocalcacheAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request Forgery.This issue affects GravatarLocalCache: from n/a through <= 1.1.2.
AplazadaMedia (4.3)0.17%—WP User Profile AvatarAI16/1/202517/6/2026
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which…
AplazadaMedia (6.5)0.23%—Paul Bearne Author AvatarsAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23.
AplazadaAlta (7.1)0.44%—Enrico Cantori 3D Avatar User ProfileAI16/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D Avatar User Profile 3d-avatar-user-profile allows Reflected XSS.This issue affects 3D Avatar User Profile: from n/a through <= 1.0.0.
AplazadaMedia (4.3)0.34%—10up Simple Local AvatarsAI16/11/202417/6/2026
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear user…
AplazadaMedia (6.5)0.26%—Paul Bearne Author Avatars List BlockAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.21.
AnalizadaAlta (8.8)0.21%—10up Simple Local Avatars26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
AnalizadaMedia (5.4)0.42%—Wpeventsmanager User Profile Avatar15/4/202417/6/2026
The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.3)0.40%—Wp-eventmanager User Profile Avatar22/1/202417/6/2026
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
ModificadaMedia (5.4)0.39%—Bearne Author Avatars List/block14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.17.
ModificadaAlta (8.8)0.32%—Petersterling ADD Local Avatar18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1.
ModificadaMedia (6.1)0.41%—Enejbajgoric/gagansandhu/ctltdev User Avatar8/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.