Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.23% | — | Phpgurukul User Registration Login AND User Management SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect… | |
| Aplazada | Crítica (9.1) | 0.18% | 💥 PoC | GistAI | 4/10/2026 | 6/10/2026 | The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login… | |
| Aplazada | Media (6.4) | 0.19% | — | Wpmet WP Social Login AND Register Social CounterAI | 3/10/2026 | 6/10/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Baja (3.7) | 0.17% | — | Genetechsolutions PIE RegisterAI | 3/10/2026 | 6/10/2026 | The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code. | |
| Aplazada | Media (6.5) | 0.28% | — | Eventtickets Event Tickets AND RegistrationAI | 2/10/2026 | 2/10/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.20% | — | Genetechsolutions PIE RegisterAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a through 3.8.4.13. | |
| Aplazada | Baja (2) | 0.32% | — | Webkul BagistoAI | 28/9/2026 | 29/9/2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now… | |
| Aplazada | Media (4.4) | 0.19% | — | OTP Login Register WoocommerceAI | 19/9/2026 | 21/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and… | |
| Aplazada | Alta (8.1) | 0.51% | — | Zotregistry ZOTAI | 18/9/2026 | 30/9/2026 | zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete… | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure Container Registry | 17/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.5) | 0.32% | — | Choose User Role AT RegistrationAI | 17/9/2026 | 18/9/2026 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation… | |
| Aplazada | Alta (8.8) | 0.45% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify… | |
| Aplazada | Alta (8.1) | 0.39% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods. | |
| Aplazada | Media (6.5) | 0.46% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components. | |
| Aplazada | Alta (8.7) | 0.60% | — | MagistralaAI | 14/9/2026 | 23/9/2026 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 14/9/2026 | A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 15/9/2026 | A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 19/9/2026 | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (3.7) | 0.28% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile… | |
| Aplazada | Alta (7.5) | 0.32% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan… | |
| Aplazada | Media (4.7) | 0.29% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing. | |
| Aplazada | Alta (7.2) | 0.46% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to… | |
| Aplazada | Alta (8.1) | 0.21% | — | Socketdev Socket-registry-firewallAIOpenrestyAI | 12/9/2026 | 22/9/2026 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and… | |
| Aplazada | Media (5.3) | 0.32% | — | OTP Login Register WoocommerceAI | 11/9/2026 | 11/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled… |