Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Davidartiss Simple-draft-listAI | 18/8/2026 | 20/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Simple JWT LoginAI | 16/8/2026 | 26/8/2026 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Simple Doctors Appointment SystemAI | 14/8/2026 | 18/8/2026 | A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Client Management SystemAI | 14/8/2026 | 14/8/2026 | A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Student Information SystemAI | 13/8/2026 | 14/8/2026 | A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Doctors Appointment SystemAI | 10/8/2026 | 12/8/2026 | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Doctors Appointment SystemAI | 7/8/2026 | 12/8/2026 | A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to… | |
| Aplazada | Baja (2.5) | 0.14% | — | Perl File Rotate SimpleAI | 7/8/2026 | 26/8/2026 | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target),… | |
| Aplazada | Media (5.3) | 0.16% | — | Simple Captcha With Cloudflare TurnstileAI | 7/8/2026 | 26/8/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and… | |
| Aplazada | Media (5.3) | 0.16% | — | Simple-membership-plugin Simple MembershipAI | 6/8/2026 | 26/8/2026 | The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they… | |
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | |
| Aplazada | Media (6.4) | 0.35% | — | Simple Yearly ArchiveAI | 5/8/2026 | 12/8/2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.32% | — | Simple Google Calendar Outlook Events WidgetAI | 4/8/2026 | 26/8/2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request. | |
| Aplazada | Media (6.1) | 0.27% | — | Simple-membership-plugin Simple MembershipAI | 3/8/2026 | 26/8/2026 | The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Simple-membership-plugin Simple MembershipAI | 3/8/2026 | 26/8/2026 | The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over… | |
| Aplazada | Baja (2.7) | 0.30% | — | Wpchill Simple RestrictAI | 2/8/2026 | 26/8/2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with… | |
| Aplazada | Alta (7.2) | 0.27% | — | Simple Link Directory PROAI | 27/7/2026 | 28/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | |
| Aplazada | Media (4.4) | 0.21% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Really Simple CSV ImporterAI | 23/7/2026 | 23/7/2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Simple Link Directory PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | |
| Aplazada | Media (5.5) | 0.69% | — | Newpanjing SimpleuiAI | 19/7/2026 | 21/7/2026 | A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and… | |
| Analizada | Alta (7.1) | 0.22% | — | Simplesamlphp | 17/7/2026 | 30/7/2026 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking… | |
| Aplazada | Alta (8.6) | 0.96% | — | SimplechatAI | 16/7/2026 | 16/7/2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET… |