Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (8.1)0.46%—Simple-gitAI29/9/202630/9/2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path…
AplazadaAlta (8.8)0.25%—CmsimpleAI22/9/202625/9/2026
CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker…
AplazadaMedia (5.3)0.42%—Really-simple-plugins Really Simple SecurityAI18/9/202618/9/2026
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
AplazadaMedia (5.3)0.29%—Simple-membership-plugin Simple MembershipAI17/9/202617/9/2026
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
AplazadaBaja (2.3)0.36%—Really-simple-plugins Really Simple SecurityAI14/9/202619/9/2026
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a…
AplazadaAlta (7.5)0.34%—Really-simple-plugins Really Simple SecurityAI13/9/202614/9/2026
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
AplazadaMedia (5.4)0.23%—Simple-membership-plugin Simple MembershipAI13/9/202614/9/2026
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
AplazadaMedia (6.5)0.22%—Idokd Simple PaymentAI11/9/202611/9/2026
Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
AplazadaCrítica (9.8)0.55%—Getsimple CMSAIGetsimple CMS CEAI11/9/202630/9/2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security…
AplazadaMedia (6.5)0.31%—Simple Captcha With Cloudflare TurnstileAI11/9/202611/9/2026
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaAlta (7.2)0.49%—Plugin-planet Simple Ajax ChatAI11/9/202611/9/2026
The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaMedia (5.6)0.25%—Simple Cloudflare TurnstileAI10/9/202610/9/2026
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
AplazadaAlta (8.8)0.67%—CmsimpleAICmsimple CoauthorsAI8/9/20269/9/2026
A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature.
AplazadaBaja (2.1)0.47%—Sourcecodester Simple Traffic Offense SystemAI7/9/202611/9/2026
A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of…
AplazadaMedia (5.5)0.76%—Sourcecodester Simple Traffic Offense SystemAI7/9/20268/9/2026
A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The…
AplazadaMedia (5.5)0.69%—Sourcecodester Simple Traffic Offense SystemAI7/9/20269/9/2026
A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now…
AplazadaAlta (7.4)0.39%—Really Simple SSLAI3/9/20263/9/2026
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
AplazadaAlta (7.1)0.25%—Idokd Simple PaymentAI3/9/20263/9/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
AplazadaMedia (5.4)0.14%—Simple Membership Mailchimp IntegrationAI2/9/20263/9/2026
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is…
AplazadaMedia (5.3)0.40%—Really Simple SSLAI2/9/20262/9/2026
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
AplazadaAlta (8.8)0.51%—Plugin-planet Simple Ajax ChatAI2/9/20263/9/2026
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
AplazadaMedia (5.3)0.58%—Simple-membership-plugin Simple MembershipAI1/9/20261/9/2026
The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite environments, where the plugin binds new Simple…
AplazadaBaja (2.1)0.47%—Code-projects Simple Inventory SystemAI31/8/20261/9/2026
A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the…
AplazadaMedia (5.5)0.53%—Code-projects Simple Inventory SystemAI31/8/202631/8/2026
A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been…
AplazadaMedia (6.6)0.43%—Really-simple-plugins Really Simple SecurityAI30/8/202631/8/2026
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the…