Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

2143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.58%—Cmsmadesimple CMS Made Simple6/7/202317/6/2026
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
ModificadaAlta (8.8)49%💥 ExploitCmsmadesimple CMS Made Simple6/7/202317/6/2026
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
ModificadaMedia (4.3)0.38%—Implecode Product Catalog Simple1/7/202317/6/2026
The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to update product meta via a…
ModificadaMedia (6.1)0.39%—Simplephpscripts Guestbook Script30/6/202317/6/2026
Se ha encontrado una vulnerabilidad en SimplePHPscripts GuestBook Script v2.2. Se ha clasificado como problemática. Esto afecta a una parte desconocida del archivo "preview.php" del componente "URL Parameter Handler". La manipulación conduce a Cross-Site Scripting (XSS). Es posible iniciar el ataque de forma remota.…
ModificadaMedia (6.1)0.39%—Simplephpscripts Event Script30/6/202317/6/2026
A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is some unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. It is recommended to…
ModificadaMedia (6.1)0.39%—Simplephpscripts Simple Blog30/6/202317/6/2026
A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. It is…
ModificadaMedia (6.1)0.50%—Simplephpscripts Classified ADS Script PHP29/6/202317/6/2026
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can…
ModificadaMedia (6.1)0.50%—Simplephpscripts Classified ADS Script PHP29/6/202317/6/2026
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack…
ModificadaMedia (4.8)0.37%—Simplemodal Contact Form Project Simplemodal Contact Form26/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= 1.2.9 versions.
ModificadaMedia (5.4)0.36%—Simple Vimeo Shortcode Project Simple Vimeo Shortcode21/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2.9.1 versions.
ModificadaCrítica (9.8)0.85%—Simple Customer Relationship Management Project Simple Customer Relationship Management16/6/202317/6/2026
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
ModificadaMedia (4.8)0.37%—Simple Slug Translate Project Simple Slug Translate16/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versions.
ModificadaAlta (7.5)8.7%💥 ExploitOssrs Simple Realtime Server12/6/202317/6/2026
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may send a request to the `/api/v1/snapshots` endpoint containing any commands to be…
ModificadaMedia (6.1)0.47%—Simpleredak2/6/202317/6/2026
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php.
ModificadaCrítica (9.8)0.85%—Simpleredak2/6/202317/6/2026
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity parameter.
ModificadaMedia (6.1)0.47%—Simpleredak2/6/202317/6/2026
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php.
ModificadaMedia (5.4)0.47%—Simpleredak1/6/202317/6/2026
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>.
ModificadaCrítica (9.8)0.82%—Simple Chat System Project Simple Chat System31/5/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=read_msg of the component POST Parameter Handler. The manipulation of the argument convo_id leads to sql injection. The attack…
ModificadaMedia (5.9)0.57%—GO Simple Tunnel Project GO Simple Tunnel30/5/202317/6/2026
Gost (GO Simple Tunnel) es un túnel simple escrito en golang. Secretos sensibles como contraseñas, tokens y claves API deben ser comparados sólo usando una función de comparación en tiempo constante. La entrada no fiable, procedente de una cabecera HTTP, se compara directamente con un secreto. Como esta comparación no…
ModificadaAlta (8.8)0.27%—Simplesharebuttons Simple Share Buttons Adder25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions.
ModificadaMedia (5.5)0.23%—Simpledesign Diary With Lock\24/5/202317/6/2026
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the…
ModificadaAlta (8.8)0.27%—SRS Simple Hits Counter Project SRS Simple Hits Counter22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Atif N SRS Simple Hits Counter plugin <= 1.1.0 versions.
ModificadaCrítica (9.8)0.72%—Simple Photo Gallery Project Simple Photo Gallery17/5/202317/6/2026
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability.
ModificadaMedia (4.8)0.39%—Simple Tooltips Project Simple Tooltips12/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Justin Saad Simple Tooltips plugin <= 2.1.4 versions.
ModificadaMedia (4.8)0.37%—Simple Popup Project Simple Popup10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb ur Rehman Simple PopUp plugin <= 1.8.6 versions.