Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.26% | — | 1xinternet Simple Klaro | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. | |
| Analizada | Baja (2) | 0.29% | — | Code-projects Simple Laundry System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unknown processing of the file /data/insert_type.php. The manipulation of the argument Type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2) | 0.29% | — | Code-projects Simple Laundry System | 6/6/2025 | 17/6/2026 | A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /data/edit_type.php. The manipulation of the argument Type leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 0.27% | — | Code-projects Simple Laundry System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2) | 0.31% | — | Code-projects Simple Laundry System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Baja (2) | 0.31% | — | Code-projects Simple Laundry System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/insert_laundry.php. The manipulation of the argument Customer leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.20% | — | Mostafa Shahiri Simple Nested MenuAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Simple Nested Menu simple-nested-menu allows Stored XSS.This issue affects Simple Nested Menu: from n/a through <= 1.0. | |
| Aplazada | Media (5.9) | 0.21% | — | Simple-membership-plugin Simple MembershipAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership simple-membership allows Stored XSS.This issue affects Simple Membership: from n/a through <= 4.6.3. | |
| Aplazada | Media (6.5) | 0.25% | — | Implecode Product Catalog SimpleAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Alessandro Piconi Simple Keyword TO LinkAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.25% | — | Youtube-simple-galleryAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer YouTube Simple Gallery youtube-simple-gallery allows Stored XSS.This issue affects YouTube Simple Gallery: from n/a through <= 2.2.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Simple Google Static MAPAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ángel C. Simple Google Static Map simple-google-static-map allows DOM-Based XSS.This issue affects Simple Google Static Map: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.9) | 0.45% | — | Simple-history Simple HistoryAI | 6/6/2025 | 17/6/2026 | The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sanitization within the append_debug_info_to_context() function in versions prior to 5.8.1. When Detective Mode is enabled, the plugin’s logger captures the entire contents of $_POST (and sometimes raw… | |
| Analizada | Media (6.5) | 0.22% | — | Pluginsandsnippets Simple Page Access Restriction | 30/5/2025 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (8.6) | 0.93% | — | Getsimple-ce Getsimple CMS | 30/5/2025 | 17/6/2026 | GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to be patched in… | |
| Analizada | Media (4.8) | 0.31% | — | Razormist Simple Computer Store System | 28/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer overflow. An attack has to be approached locally. The exploit… | |
| Analizada | Media (5.1) | 0.35% | — | Cmsmadesimple CMS Made Simple | 25/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design Manager Module. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Quantumcloud Simple Business Directory PROAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Media (6.4) | 0.36% | — | SimplelightboxAI | 20/5/2025 | 17/6/2026 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.31% | — | Quantumcloud Simple Link DirectoryAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Analizada | Media (5.9) | 0.30% | — | Archetyped Simple Lightbox | 16/5/2025 | 17/6/2026 | The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Media (4.3) | 0.17% | — | Philipwalton Simple NAV Archives | 15/5/2025 | 17/6/2026 | The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Baja (3.7) | 0.40% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes | |
| Analizada | Media (6.1) | 0.36% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor | |
| Analizada | Media (4.8) | 0.32% | — | Missionmike Simple Share | 15/5/2025 | 17/6/2026 | The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |