Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.33% | — | Codeastro Simple Banking System | 7/10/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processing of the file /createuser.php. Performing manipulation of the argument Name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (6.4) | 0.19% | — | A Simple Multilanguage PluginAI | 3/10/2025 | 17/6/2026 | The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'asmp-switcher' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Simple Scheduling System | 28/9/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown functionality of the file /addtime.php. The manipulation of the argument starttime/endtime leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Simple Scheduling System | 28/9/2025 | 30/9/2026 | A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Other parameters might be affected… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Simple Scheduling System | 28/9/2025 | 17/6/2026 | A vulnerability was determined in code-projects Simple Scheduling System 1.0. Impacted is an unknown function of the file /schedulingsystem/addroom.php. Executing manipulation of the argument room can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Simple Scheduling System | 28/9/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Scheduling System 1.0. This issue affects some unknown processing of the file /schedulingsystem/addcourse.php. Performing manipulation of the argument corcode results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Simple Scheduling System | 28/9/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Scheduling System 1.0. This vulnerability affects unknown code of the file /schedulingsystem/addfaculty.php. Such manipulation of the argument falname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Simple Scheduling System | 28/9/2025 | 17/6/2026 | A flaw has been found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /schedulingsystem/addsubject.php. This manipulation of the argument subcode causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Media (6.5) | 0.21% | — | Dagang LEV Simple Meta TagsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DaganLev Simple Meta Tags simple-meta-tags allows DOM-Based XSS.This issue affects Simple Meta Tags: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Ryan Hellyer Simple ColorboxAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Hellyer Simple Colorbox simple-colorbox allows Stored XSS.This issue affects Simple Colorbox: from n/a through <= 1.6.1. | |
| Analizada | Baja (2) | 0.24% | — | Fabian Simple Food Ordering System | 23/9/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /ordersimple/order.php. The manipulation of the argument ID leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.21% | — | Nicu Micle Simple JWT LoginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicu Micle Simple JWT Login simple-jwt-login allows Stored XSS.This issue affects Simple JWT Login: from n/a through <= 3.6.4. | |
| Aplazada | Media (5.9) | 0.22% | — | Will.i.am Simple Restaurant MenuAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will.I.am Simple Restaurant Menu simple-restaurant-menu allows Stored XSS.This issue affects Simple Restaurant Menu: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Implecode Product Catalog SimpleAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.2. | |
| Analizada | Baja (2.1) | 0.34% | — | Oretnom23 Simple Forum/discussion System | 22/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Simple Forum Discussion System 1.0. This affects an unknown function of the file /ajax.php?action=save_category. The manipulation of the argument Description results in sql injection. The attack can be executed remotely. The exploit has been released to the public… | |
| Analizada | Baja (2.1) | 0.34% | — | Codeastro Simple Pharmacy Management System | 22/9/2025 | 17/6/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file /view.php. This manipulation of the argument bar_code causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (6.6) | 0.80% | — | Developer Loggers FOR Simple HistoryAI | 17/9/2025 | 25/9/2026 | The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the enabled_loggers parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on… | |
| Aplazada | Alta (8.8) | 0.41% | — | Simple-swizzleAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions… | |
| Aplazada | Media (6.5) | 0.32% | — | Wpsimplebookingcalendar WP Simple Booking CalendarAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calendar: from n/a through <= 2.0.13. | |
| Analizada | Baja (2) | 0.32% | — | Chuck24 Simple To-do List System | 9/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. Executing manipulation with the input <script>alert('XSS')</script> can lead to cross site scripting. The attack can be executed remotely. The… | |
| Analizada | Media (5.5) | 0.42% | — | Oretnom23 Simple Forum/discussion System | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be… | |
| Aplazada | Media (6.5) | 0.17% | — | W1zzard Simple Text SliderAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider simple-text-slider allows Stored XSS.This issue affects Simple Text Slider: from n/a through <= 1.0.5. | |
| Aplazada | Alta (8.5) | 0.27% | — | Gopiplus NEW Simple GalleryAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects New Simple Gallery: from n/a through <= 8.0. | |
| Aplazada | Media (6.5) | 0.29% | — | Premiumbizthemes Simple Price CalculatorAI | 5/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in premiumbizthemes Simple Price Calculator simple-price-calculator-basic allows Retrieve Embedded Sensitive Data.This issue affects Simple Price Calculator: from n/a through <= 1.3. | |
| Aplazada | Media (5.9) | 0.22% | — | Jimmywb Simple Link List WidgetAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jimmywb Simple Link List Widget simple-link-list-widget allows Stored XSS.This issue affects Simple Link List Widget: from n/a through <= 0.3.2. |