Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.25% | — | Getsimple-ce Getsimple CMS | 18/12/2024 | 17/6/2026 | GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module. | |
| Analizada | Alta (7.2) | 0.41% | — | Getsimple-ce Getsimple CMS | 18/12/2024 | 17/6/2026 | In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system. | |
| Analizada | Crítica (9.8) | 0.86% | — | Getsimple-ce Getsimple CMS | 16/12/2024 | 17/6/2026 | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE. | |
| Analizada | Media (6.9) | 0.38% | — | Get-simple Getsimplecms | 12/11/2024 | 17/6/2026 | A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Modificada | Media (6.1) | 0.27% | — | Harpreetsingh Ajax Custom Css/js | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harry005 Ajax Custom CSS/JS ajax-awesome-css allows Reflected XSS.This issue affects Ajax Custom CSS/JS: from n/a through <= 2.0.4. | |
| Analizada | Baja (2.1) | 0.27% | — | Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+23 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <… | |
| Analizada | Media (5.3) | 0.30% | — | Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+23 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <… | |
| Analizada | Media (6.9) | 0.41% | — | Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+23 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <… | |
| Analizada | Media (5.9) | 0.41% | — | Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+23 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <… | |
| Analizada | Media (6) | 0.35% | — | Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+23 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <… | |
| Analizada | Alta (7) | 0.41% | — | Siemens Simatic Rf360r FirmwareSiemens Simatic Rf1170r FirmwareSiemens Simatic Rf1140r FirmwareSiemens Simatic Reader Rf685r FCC Firmware+23 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions <… | |
| Modificada | Media (5.4) | 0.33% | — | Get-simple Getsimplecms | 8/1/2024 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page. | |
| Modificada | Crítica (9.8) | 0.97% | — | Get-simple Getsimplecms | 17/11/2023 | 17/6/2026 | A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.50% | — | Get-simple Getsimplecms | 31/10/2023 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function. | |
| Modificada | Crítica (9.8) | 23% | — | Get-simple Getsimplecms | 19/10/2023 | 17/6/2026 | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo(). | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Get-simple Getsimple CMS | 18/10/2022 | 17/6/2026 | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. | |
| Modificada | Media (5.4) | 0.66% | — | Get-simple Getsimple CMS | 27/4/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> leads to cross site scripting. The attack may be launched remotely… | |
| Modificada | Media (6.1) | 0.94% | — | Get-simple Getsimplecms | 10/8/2021 | 17/6/2026 | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter. | |
| Modificada | Media (5.4) | 0.55% | — | Get-simple Getsimplecms | 6/8/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module. | |
| Modificada | Media (6.1) | 1.3% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php | |
| Modificada | Media (6.1) | 1.4% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php. | |
| Modificada | Media (6.1) | 1.4% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function. | |
| Modificada | Media (5.4) | 0.58% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets. | |
| Modificada | Media (4.8) | 0.59% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php. |