Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Codection Import AND Export Users AND CustomersAI | 30/9/2026 | 30/9/2026 | Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions. | |
| Aplazada | Alta (8.8) | 0.33% | — | Codection Import AND Export Users AND CustomersAI | 23/9/2026 | 24/9/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape… | |
| Aplazada | Alta (7.2) | 0.46% | — | Codection Import AND Export Users AND CustomersAI | 20/9/2026 | 21/9/2026 | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator. | |
| Aplazada | Alta (7.2) | 0.46% | — | Codection Import AND Export Users AND CustomersAI | 20/9/2026 | 21/9/2026 | The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator. | |
| Aplazada | Media (4.1) | 0.18% | — | Codection Import AND Export Users AND CustomersAI | 20/9/2026 | 21/9/2026 | The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks. | |
| Aplazada | Alta (8.1) | 0.38% | — | Ayecode UserswpAI | 19/9/2026 | 21/9/2026 | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider… | |
| Aplazada | Media (5.3) | 0.44% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string… | |
| Aplazada | Alta (8.1) | 0.41% | — | Ayecode UserswpAI | 11/9/2026 | 11/9/2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue… | |
| Pendiente de análisis | Media (5.1) | 0.11% | — | ARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Valhall GPU Userspace Driver:… | |
| Pendiente de análisis | Alta (8.6) | 1.6% | — | Suse Yast2-usersAI | 1/9/2026 | 2/9/2026 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to… | |
| Aplazada | Media (6.4) | 0.26% | — | Ayecode UserswpAI | 6/8/2026 | 12/8/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Codection Import AND Export Users AND CustomersAI | 3/8/2026 | 26/8/2026 | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or… | |
| Aplazada | Media (4.9) | 0.47% | — | Codection Import AND Export Users AND CustomersAI | 3/8/2026 | 29/9/2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Pouco Import UsersAI | 2/8/2026 | 26/8/2026 | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and… | |
| Aplazada | Alta (7.4) | 0.41% | — | Ayecode UserswpAI | 29/7/2026 | 30/7/2026 | The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user. | |
| Aplazada | Media (5.3) | 0.40% | — | Huggingface DiffusersAI | 23/7/2026 | 23/7/2026 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 23/7/2026 | 28/7/2026 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it… | |
| Aplazada | Alta (7.5) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 23/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF,… | |
| Aplazada | Media (6.5) | 0.42% | — | Regularlabs Users AnywhereAIRegularlabs Articles AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details. | |
| Analizada | Alta (7.5) | 0.37% | — | Huggingface Diffusers | 15/7/2026 | 12/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub… | |
| Aplazada | Media (4.3) | 0.39% | — | Codection Import AND Export Users AND CustomersAI | 10/7/2026 | 10/7/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw… | |
| Aplazada | Alta (8.8) | 0.69% | — | Ayecode UserswpAI | 9/7/2026 | 10/7/2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving… | |
| Aplazada | Baja (2.7) | 0.27% | — | Ayecode UserswpAI | 18/6/2026 | 18/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Crítica (9.3) | 0.43% | — | UserspiceAI | 23/5/2026 | 23/7/2026 | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the… |