Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.25%—Getsimple-ce Getsimple CMS18/12/202417/6/2026
GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
AnalizadaAlta (7.2)0.41%—Getsimple-ce Getsimple CMS18/12/202417/6/2026
In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system.
AnalizadaCrítica (9.8)0.86%—Getsimple-ce Getsimple CMS16/12/202417/6/2026
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.
AnalizadaMedia (6.9)0.38%—Get-simple Getsimplecms12/11/202417/6/2026
A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor…
ModificadaMedia (6.1)0.27%—Harpreetsingh Ajax Custom Css/js18/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harry005 Ajax Custom CSS/JS ajax-awesome-css allows Reflected XSS.This issue affects Ajax Custom CSS/JS: from n/a through <= 2.0.4.
AnalizadaBaja (2.1)0.27%—Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+2310/9/202417/6/2026
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <…
AnalizadaMedia (5.3)0.30%—Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+2310/9/202417/6/2026
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <…
AnalizadaMedia (6.9)0.41%—Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+2310/9/202417/6/2026
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <…
AnalizadaMedia (5.9)0.41%—Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+2310/9/202417/6/2026
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <…
AnalizadaMedia (6)0.35%—Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+2310/9/202417/6/2026
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <…
AnalizadaAlta (7)0.41%—Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+2310/9/202417/6/2026
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <…
ModificadaMedia (5.4)0.33%—Get-simple Getsimplecms8/1/202417/6/2026
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.
ModificadaCrítica (9.8)0.97%—Get-simple Getsimplecms17/11/202317/6/2026
A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (5.4)0.50%—Get-simple Getsimplecms31/10/202317/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function.
ModificadaCrítica (9.8)23%—Get-simple Getsimplecms19/10/202317/6/2026
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().
ModificadaCrítica (9.8)11%💥 ExploitGet-simple Getsimple CMS18/10/202217/6/2026
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.
ModificadaMedia (5.4)0.66%—Get-simple Getsimple CMS27/4/202217/6/2026
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> leads to cross site scripting. The attack may be launched remotely…
ModificadaMedia (6.1)0.94%—Get-simple Getsimplecms10/8/202117/6/2026
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter.
ModificadaMedia (5.4)0.55%—Get-simple Getsimplecms6/8/202117/6/2026
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
ModificadaMedia (6.1)1.3%—Get-simple Getsimplecms23/6/202117/6/2026
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
ModificadaMedia (6.1)1.3%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
ModificadaMedia (6.1)1.4%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
ModificadaMedia (6.1)1.4%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
ModificadaMedia (5.4)0.58%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
ModificadaMedia (4.8)0.59%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.
Orbitaley — Vulnerabilidades