Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.32%—Codection Import AND Export Users AND CustomersAI30/9/202630/9/2026
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
AplazadaAlta (8.8)0.33%—Codection Import AND Export Users AND CustomersAI23/9/202624/9/2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape…
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
AplazadaMedia (4.1)0.18%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
AplazadaAlta (8.1)0.38%—Ayecode UserswpAI19/9/202621/9/2026
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider…
AplazadaMedia (5.3)0.44%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI14/9/202616/9/2026
Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string…
AplazadaAlta (8.1)0.41%—Ayecode UserswpAI11/9/202611/9/2026
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls…
Pendiente de análisisAlta (7.8)0.16%—ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue…
Pendiente de análisisMedia (5.1)0.11%—ARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Valhall GPU Userspace Driver:…
Pendiente de análisisAlta (8.6)1.6%—Suse Yast2-usersAI1/9/20262/9/2026
An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to…
AplazadaMedia (6.4)0.26%—Ayecode UserswpAI6/8/202612/8/2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This…
AplazadaCrítica (9.1)0.40%—Codection Import AND Export Users AND CustomersAI3/8/202626/8/2026
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or…
AplazadaMedia (4.9)0.47%—Codection Import AND Export Users AND CustomersAI3/8/202629/9/2026
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
AplazadaCrítica (9.8)0.50%—Pouco Import UsersAI2/8/202626/8/2026
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and…
AplazadaAlta (7.4)0.41%—Ayecode UserswpAI29/7/202630/7/2026
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
AplazadaMedia (5.3)0.40%—Huggingface DiffusersAI23/7/202623/7/2026
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to…
AplazadaAlta (7.5)0.42%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI23/7/202628/7/2026
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it…
AplazadaAlta (7.5)0.43%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI23/7/202627/7/2026
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF,…
AplazadaMedia (6.5)0.42%—Regularlabs Users AnywhereAIRegularlabs Articles AnywhereAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
AnalizadaAlta (7.5)0.37%—Huggingface Diffusers15/7/202612/8/2026
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub…
AplazadaMedia (4.3)0.39%—Codection Import AND Export Users AND CustomersAI10/7/202610/7/2026
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw…
AplazadaAlta (8.8)0.69%—Ayecode UserswpAI9/7/202610/7/2026
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving…
AplazadaBaja (2.7)0.27%—Ayecode UserswpAI18/6/202618/6/2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it…
AplazadaCrítica (9.3)0.43%—UserspiceAI23/5/202623/7/2026
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the…