Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.65% | — | Quantumcloud Simple Video Directory | 15/5/2025 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Analizada | Media (4.8) | 0.31% | — | Wpkube Simple Basic Contact Form | 15/5/2025 | 17/6/2026 | The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.37% | — | Fabian Simple Hospital Management System | 10/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component Add Information. The manipulation of the argument x[i].name/x[i].disease leads to stack-based buffer overflow. The attack needs to be approached… | |
| Analizada | Media (4.8) | 0.37% | — | Fabian Simple BUS Reservation System | 10/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has… | |
| Analizada | Media (4.8) | 0.40% | — | Code-projects Simple Banking System | 10/5/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the… | |
| Analizada | Media (4.8) | 0.40% | — | Fabian Simple College Management System | 9/5/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This vulnerability affects the function input of the component Add New Student. The manipulation of the argument name/branch leads to stack-based buffer overflow. It is possible to launch the attack on… | |
| Aplazada | Media (4.6) | 0.27% | — | Simple Python EncryptionAI | 8/5/2025 | 17/6/2026 | Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versions prior to commit 6ce60b1, an attacker may be able to decrypt the data using brute force attacks and because of this the whole application can be impacted. This issue has been patched in commit… | |
| Aplazada | Media (4.3) | 0.17% | — | Ibenic Simple GiveawaysAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways giveasap allows Cross Site Request Forgery.This issue affects Simple Giveaways: from n/a through <= 2.49.0. | |
| Aplazada | Media (5.9) | 0.27% | — | Jonashjalmarsson Really Simple Under Construction PageAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonas Hjalmarsson Really Simple Under Construction Page really-simple-under-construction allows Stored XSS.This issue affects Really Simple Under Construction Page: from n/a through <= 1.4.6. | |
| Modificada | Media (4.3) | 0.17% | — | Migaweb Simple Calendar FOR Elementor | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This issue affects Simple calendar for Elementor: from n/a through <= 1.6.5. | |
| Aplazada | Media (6.5) | 0.26% | — | Jeff Starr Simple Blog StatsAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Blog Stats simple-blog-stats allows Stored XSS.This issue affects Simple Blog Stats: from n/a through <= 20250416. | |
| Aplazada | Media (5.3) | 0.33% | — | Simplefilelist Simple File ListAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.13. | |
| Analizada | Media (5.3) | 0.55% | — | Chuck24 Simple To-do List System | 4/5/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /complete_task.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.53% | — | Chuck24 Simple To-do List System | 4/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is an unknown function of the file /delete_task.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.4) | 0.28% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.36% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a… | |
| Analizada | Media (6.5) | 0.41% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add… | |
| Analizada | Alta (7.3) | 0.36% | — | Oretnom23 Simple Barangay Management System | 30/4/2025 | 17/6/2026 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household. | |
| Analizada | Alta (7.6) | 0.34% | — | Oretnom23 Simple Barangay Management System | 30/4/2025 | 17/6/2026 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Simple Barangay Management System | 30/4/2025 | 17/6/2026 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance. | |
| Modificada | Alta (8.8) | 0.39% | — | Wpgoplugins Simple Sitemap | 30/4/2025 | 17/6/2026 | Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap – Create a Responsive HTML Sitemap: from n/a through <= 3.6.0. | |
| Analizada | Media (4.8) | 0.37% | — | Fabian Simple Movie Ticket Booking System | 29/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation of the argument prize leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to… | |
| Aplazada | Media (4.9) | 0.23% | — | Josheli Simple Google Photos GridAI | 24/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in josheli Simple Google Photos Grid simple-google-photos-grid allows Server Side Request Forgery.This issue affects Simple Google Photos Grid: from n/a through <= 1.5. | |
| Modificada | Media (4.8) | 0.28% | — | Castos Seriously Simple Podcasting | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.9.0. | |
| Aplazada | Alta (7.5) | 0.53% | — | Wordpress Simple Shopping CartAI | 23/4/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a… |