Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.45% | — | Simple User CapabilitiesAI | 4/11/2025 | 17/6/2026 | The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to elevate the role of any user account to administrator. | |
| Aplazada | Media (5.3) | 0.29% | — | Simple User CapabilitiesAI | 4/11/2025 | 17/6/2026 | The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to reset any user's capabilities. | |
| Analizada | Media (4.6) | 0.21% | — | Nababur Simple-user-management-system | 3/11/2025 | 17/6/2026 | Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser | |
| Modificada | Baja (2) | 0.44% | — | Fabian Simple Online Hotel Reservation System | 2/11/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation of the argument Name results in sql injection. The attack may be performed from remote. The exploit has been released to the public and… | |
| Analizada | Baja (2) | 0.43% | — | Fabian Simple Online Hotel Reservation System | 2/11/2025 | 17/6/2026 | A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is… | |
| Analizada | Alta (7.5) | 0.36% | — | Simple Oauth Project Simple Oauth | 30/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7. | |
| Analizada | Media (5.5) | 0.53% | — | Fabian Simple Food Ordering System | 28/10/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public… | |
| Analizada | Baja (2.1) | 0.39% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may… | |
| Analizada | Media (5.5) | 0.53% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.php. This manipulation of the argument cname causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2.1) | 0.39% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The manipulation of the argument pname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Food Ordering System | 27/10/2025 | 1/10/2026 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple E-banking System | 27/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /eBank/register.php. Executing manipulation of the argument Username can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (6.5) | 0.17% | — | Llamaman Simple Pull QuoteAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in llamaman Simple Pull Quote simple-pull-quote allows Stored XSS.This issue affects Simple Pull Quote: from n/a through <= 1.6.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Clifton Griffin Simple Content Templates FOR Blog Posts AND PagesAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Clifton Griffin Simple Content Templates for Blog Posts & Pages simple-post-template allows Cross Site Request Forgery.This issue affects Simple Content Templates for Blog Posts & Pages: from n/a through <= 2.2.61. | |
| Modificada | Media (4.3) | 0.24% | — | Castos Seriously Simple Podcasting | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0. | |
| Aplazada | Alta (8.8) | 0.20% | — | Simple Registration FOR WoocommerceAI | 25/10/2025 | 17/6/2026 | The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.8. This is due to missing nonce validation on the role requests admin page handler in the includes/display-role-admin.php file. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.26% | — | Simpledns Simple DNS PlusAI | 24/10/2025 | 17/6/2026 | Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server to return request payloads from other clients. This happens when the TCP length prefix is malformed (len differs from actual packet len), and due to a concurrency/buffering issue,… | |
| Aplazada | Media (6.4) | 0.19% | — | Simple Excel Pricelist FOR WoocommerceAI | 24/10/2025 | 17/6/2026 | The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricelist' shortcode in all versions up to, and including, 1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.13% | — | Implecode Product Catalog SimpleAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in impleCode Product Catalog Simple post-type-x.This issue affects Product Catalog Simple: from n/a through <= 1.8.4. | |
| Aplazada | Alta (7.1) | 0.24% | — | Weissmike Simple Finance CalculatorAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weissmike Simple Finance Calculator simple-finance-calculator allows Reflected XSS.This issue affects Simple Finance Calculator: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Presstigers Simple JOB BoardAI | 22/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7. | |
| Modificada | Media (5.9) | 0.22% | — | Castos Seriously Simple Podcasting | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1. | |
| Aplazada | Crítica (9.8) | 0.73% | 💥 PoC | Quantumcloud Simple Link DirectoryAI | 22/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Alta (8.8) | 0.36% | — | Nmedia Simple User RegistrationAI | 22/10/2025 | 5/10/2026 | Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Registration: from n/a through <= 6.8. |