Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)——SimplechatAI6/10/20266/10/2026
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The…
AplazadaAlta (8.8)——SimplechatAI6/10/20266/10/2026
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that…
AplazadaAlta (7.1)0.25%—WPG Demos Woocommerce Simple AuctionsAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions.
AplazadaAlta (8.8)0.42%—Simple JWT LoginAI6/10/20266/10/2026
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
AplazadaAlta (8.6)0.36%—Simplefilelist Simple File ListAI6/10/20266/10/2026
Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.
AplazadaBaja (2.1)0.35%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely.…
AplazadaBaja (2)0.26%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly…
AplazadaMedia (6.9)0.26%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
AplazadaAlta (8.8)0.36%—Presstigers Simple Event PlannerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
AplazadaBaja (3.5)0.14%—Fabian Simple Shopping CartAI4/10/20266/10/2026
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where…
AplazadaAlta (7.5)0.37%—Simple-membership-plugin Simple MembershipAI3/10/20266/10/2026
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on…
AplazadaBaja (2.1)0.20%—Codeastro Simple Loan Management SystemAI2/10/20266/10/2026
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used…
AplazadaBaja (2.1)0.20%—Codeastro Simple Pharmacy Management SystemAI2/10/20262/10/2026
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might…
AplazadaBaja (2.1)0.20%—Codeastro Simple Pharmacy Management SystemAI2/10/20262/10/2026
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may…
AplazadaAlta (8.7)0.40%—Getsimple CMSAI1/10/20261/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is…
AplazadaAlta (7.1)0.34%—Getsimple CMSAI1/10/20261/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to…
AplazadaAlta (8.8)0.26%—Getsimplecms Getsimple CMSAI1/10/20265/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is…
AplazadaCrítica (9.6)0.22%—Getsimplecms Getsimple CMS CEAI1/10/20266/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a…
AplazadaAlta (7.5)0.26%—Getsimplecms Getsimple CMSAI1/10/20261/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An…
AplazadaCrítica (9.1)0.53%—Getsimple CMSAI1/10/20261/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written…
AplazadaCrítica (9.1)0.34%—Getsimple CMSAI1/10/20265/10/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and…
AplazadaMedia (6.9)0.18%—Simple-php-router Simple PHP RouterAI30/9/20265/10/2026
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted…
Pendiente de análisisCrítica (9.2)0.27%—Simple-gitAISimple-git Argv-parserAI29/9/202630/9/2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A…
En análisisCrítica (9.2)0.27%—Simple-gitAI29/9/202630/9/2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled…
En análisisAlta (8.1)0.36%—Simple-gitAI29/9/20262/10/2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option…