Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Idokd Simple PaymentAI | 28/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 26/8/2026 | 29/8/2026 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Simplex ChatAI | 26/8/2026 | 9/9/2026 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. | |
| Pendiente de análisis | Alta (8.6) | 0.36% | — | Simplemachines ForumAI | 26/8/2026 | 24/9/2026 | Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between… | |
| Aplazada | Media (6.5) | 0.29% | — | Simple NewsletterAI | 26/8/2026 | 26/8/2026 | The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Simple Inventory SystemAI | 25/8/2026 | 26/8/2026 | A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 24/8/2026 | A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 26/8/2026 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 24/8/2026 | A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 27/8/2026 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available… | |
| Pendiente de análisis | Media (6.9) | 0.08% | — | Johnsoncontrols Simplex Incident ManagerAIJohnsoncontrols Autocall Fire AdministratorAI | 21/8/2026 | 3/9/2026 | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05. | |
| Aplazada | Media (5.7) | 0.32% | — | Catalyst Plugin Static SimpleAI | 20/8/2026 | 28/8/2026 | Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 25/8/2026 | A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Simple Inventory SystemAI | 20/8/2026 | 24/8/2026 | A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (7.5) | 0.78% | — | Simplesamlphp Saml2AI | 19/8/2026 | 18/9/2026 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath evaluation can consume uncontrolled processing resources, allowing a remote… | |
| Aplazada | Alta (8.7) | 0.47% | — | Simplesamlphp Saml2AI | 19/8/2026 | 18/9/2026 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a… | |
| Aplazada | Alta (8.8) | 0.51% | — | Simplefilelist Simple File ListAI | 19/8/2026 | 26/8/2026 | The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any… | |
| Aplazada | Alta (8.6) | 0.73% | — | Simplefilelist Simple File ListAI | 19/8/2026 | 26/8/2026 | The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 21/8/2026 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 21/8/2026 | A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and… |