Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.51%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
ModificadaAlta (7.2)7.5%💥 ExploitGet-simple Getsimplecms23/6/202117/6/2026
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
ModificadaAlta (7.5)0.99%—Siemens Simatic Rf166c FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Rf186c FirmwareSiemens Simatic Rf186ci Firmware+218/6/202117/6/2026
A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC RF186C (All versions > V1.1 and < V1.3.2), SIMATIC RF186CI (All versions > V1.1 and < V1.3.2), SIMATIC RF188C (All versions > V1.1 and < V1.3.2), SIMATIC RF188CI (All…
ModificadaAlta (7.5)3.2%—Netsia Seba+17/1/202117/6/2026
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and can then use that…
ModificadaCrítica (9.1)2.1%—Get-simple Getsimplecms2/10/202017/6/2026
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php
ModificadaMedia (5.4)0.88%—Get-simple Getsimple CMS1/10/202017/6/2026
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
ModificadaMedia (6.1)10%💥 ExploitGet-simple Getsimple CMS1/9/202017/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.
ModificadaMedia (6.1)1.1%—Get-simple Getsimple CMS2/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to filebrowser.php in admin/. NOTE: the path…
ModificadaMedia (5.4)0.67%—Get-simple Getsimple CMS15/9/201917/6/2026
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
ModificadaCrítica (9.8)72%💥 ExploitGet-simple Getsimple CMS22/5/201917/6/2026
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). This vulnerability is triggered by an authenticated user; however, authentication can be bypassed. According to the official…
ModificadaMedia (6.1)3.6%💥 ExploitGet-simple. Getsimplecms22/3/201917/6/2026
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
ModificadaMedia (5.9)1.5%—Etsi Enterprise Transport Security26/2/201917/6/2026
The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy.
ModificadaMedia (5.4)0.57%—Get-simple Getsimple CMS31/12/201817/6/2026
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.
ModificadaBaja (3.8)0.78%—Get-simple Getsimple CMS21/11/201817/6/2026
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.
ModificadaBaja (3.8)0.78%—Get-simple Getsimple CMS21/11/201817/6/2026
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and validate_safe_file in…
ModificadaMedia (4.8)0.67%—Get-simple Getsimple CMS1/10/201817/6/2026
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
ModificadaAlta (8.8)0.65%—Get-simple Getsimple CMS16/9/201817/6/2026
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter
ModificadaMedia (6.1)0.80%—Get-simple Getsimple CMS1/9/201817/6/2026
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
ModificadaMedia (4.8)0.62%—Get-simple Getsimple CMS25/8/201817/6/2026
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
ModificadaMedia (6.1)2.4%💥 ExploitGet-simple Getsimple CMS2/4/201817/6/2026
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
ModificadaMedia (6.1)0.65%—Get-simple Getsimple CMS29/6/201717/6/2026
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
ModificadaAlta (8.8)1.3%—Cagintranetworks Getsimple CMS30/4/201717/6/2026
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.
ModificadaMedia (5.3)1.2%—Get-simple Getsimple CMS17/3/201717/6/2026
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.
ModificadaAlta (7.5)14%💥 ExploitGet-simple Getsimple CMS17/3/201717/6/2026
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.
ModificadaMedia (4.3)1.8%—Get-simple Getsimple CMS1/7/201517/6/2026
Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter.
Orbitaley — Vulnerabilidades