Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.25% | — | Marcelotorres Simple Responsive SliderAI | 12/8/2025 | 17/6/2026 | The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web… | |
| Analizada | Media (5.5) | 0.51% | — | Code-projects Simple ART Gallery | 10/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Art Gallery 1.0. Affected by this issue is some unknown functionality of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Crítica (9.3) | 1.7% | 💥 Exploit | Simple WEB ServerAI | 8/8/2025 | 16/6/2026 | Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer overflow on the stack. This flaw allows remote… | |
| Aplazada | Crítica (9.2) | 1.8% | 💥 Exploit | Simple E-documentAI | 31/7/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanism fails to restrict file types and does not validate or sanitize… | |
| Analizada | Baja (1.9) | 0.25% | — | Code-projects Simple CAR Rental System | 30/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/add_vehicles.php. The manipulation of the argument car_name leads to cross site scripting. The attack may be initiated remotely. The exploit… | |
| Analizada | Baja (2.1) | 0.23% | — | Code-projects Simple CAR Rental System | 30/7/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (8.8) | 0.17% | — | Simple-help Simplehelp | 25/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11. | |
| Analizada | Alta (8.8) | 0.44% | — | Simple-help Simplehelp | 25/7/2025 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12. | |
| Analizada | Alta (8.7) | 3.7% | 💥 Exploit | Get-simple Getsimplecms | 25/7/2025 | 16/6/2026 | An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. By uploading a .pht file containing PHP code, an attacker can bypass… | |
| Analizada | Alta (7.5) | 1.7% | — | Mywebsiteadvisor Simple Backup | 19/7/2025 | 17/6/2026 | The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the… | |
| Aplazada | Media (4.4) | 0.18% | — | Simplecoding Terms DescriptionsAI | 18/7/2025 | 17/6/2026 | The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Analizada | Media (5.5) | 0.45% | — | Fabian Simple Shopping Cart | 14/7/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.45% | — | Fabian Simple Shopping Cart | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.45% | — | Fabian Simple Shopping Cart | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.46% | — | Fabian Simple CAR Rental System | 12/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/add_cars.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Simple CAR Rental System | 12/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Simple CAR Rental System | 12/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part of the file /pay.php. The manipulation of the argument mpesa leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Crítica (9.8) | 45% | 💥 Exploit | Simplefilelist Simple File List | 12/7/2025 | 17/6/2026 | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server. | |
| Aplazada | Media (6.5) | 0.19% | — | Texas Instruments Cc2652rb LaunchpadAITexas Instruments Simplelink Cc13xx Cc26xx SDKAI | 9/7/2025 | 5/7/2026 | Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet. | |
| Aplazada | Media (6.4) | 0.25% | — | Simple Featured ImageAI | 9/7/2025 | 17/6/2026 | The Simple Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slideshow’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Baja (2) | 0.31% | — | Codeastro Simple Hospital Management System | 8/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor.html of the component POST Parameter Handler. The manipulation of the argument First Name/Last name/Address leads to cross site… | |
| Analizada | Baja (2) | 0.31% | — | Codeastro Simple Hospital Management System | 7/7/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /patient.html of the component POST Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Alta (8.5) | 0.29% | — | Quantumcloud Simple Link DirectoryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Analizada | Media (5.5) | 0.57% | — | Carmelo Simple Pizza Ordering System | 1/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editcus.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.50% | — | Carmelo Simple Pizza Ordering System | 1/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /large.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… |