Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | Mishubd WP Human Resource Management | 4/7/2025 | 17/6/2026 | The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee() function in versions 2.0.0 through 2.2.17. The plugin’s deletion handler reads the client-supplied $_POST['delete'] array and passes each ID directly to… | |
| Analizada | Alta (8.8) | 0.44% | — | Mishubd WP Human Resource Management | 4/7/2025 | 17/6/2026 | The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() functions in versions 2.0.0 through 2.2.17. The AJAX handler reads the client-supplied $_POST['role'] and, after basic cleaning via hrm_clean(),… | |
| Modificada | Alta (7.5) | 2.4% | — | Mishubd WP Human Resource Management | 5/3/2019 | 17/6/2026 | The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role. | |
| Modificada | Alta (7.5) | 1.8% | — | Mishubd WP Human Resource Management | 5/3/2019 | 17/6/2026 | The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications. |