Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.62% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Media (6.5) | 0.64% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.59% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.66% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.2% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.2% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 0.73% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 0.69% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue. | |
| Analizada | Crítica (9.8) | 2.6% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. | |
| Aplazada | Media (6.4) | 0.26% | — | Strangerstudios Paid Memberships PROAI | 28/7/2026 | 28/7/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output… | |
| Modificada | Media (5.3) | 0.34% | — | Apache Ranger | 3/3/2026 | 24/8/2026 | Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Ranger | 3/3/2026 | 17/6/2026 | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | |
| Aplazada | Media (6.5) | 0.27% | — | Strangerstudios Memberlite ShortcodesAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1. | |
| Aplazada | Media (6.4) | 0.27% | — | Strangerstudios Memberlite ShortcodesAI | 17/9/2025 | 25/9/2026 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.30% | — | Webrangers Clear Sucuri CacheAI | 28/3/2025 | 17/6/2026 | Missing Authorization vulnerability in webrangers Clear Sucuri Cache clear-sucuri-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clear Sucuri Cache: from n/a through <= 1.4. | |
| Analizada | Crítica (9.8) | 0.81% | — | Apache Ranger | 3/3/2025 | 17/6/2026 | Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue. | |
| Modificada | Crítica (9.1) | 0.64% | — | Apache Ranger | 21/1/2025 | 17/6/2026 | SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | |
| Modificada | Media (4.8) | 0.56% | — | Apache Ranger | 21/1/2025 | 17/6/2026 | Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | |
| Aplazada | Media (6.4) | 0.47% | — | Strangerstudios Memberlite ShortcodesAI | 23/11/2024 | 17/6/2026 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_accordion shortcode in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 0.67% | — | Strangerstudios Paid Memberships PRO | 1/11/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | |
| Modificada | Media (6.5) | 0.52% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. | |
| Analizada | Media (4.9) | 0.56% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. | |
| Modificada | Alta (7.2) | 0.74% | — | Strangerstudios Paid Memberships PRO | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5. | |
| Analizada | Alta (8.8) | 0.48% | — | Strangerstudios Paid Memberships PRO | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. |