Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
2143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.58% | — | Cmsmadesimple CMS Made Simple | 6/7/2023 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function. | |
| Modificada | Alta (8.8) | 49% | 💥 Exploit | Cmsmadesimple CMS Made Simple | 6/7/2023 | 17/6/2026 | CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | |
| Modificada | Media (4.3) | 0.38% | — | Implecode Product Catalog Simple | 1/7/2023 | 17/6/2026 | The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to update product meta via a… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Guestbook Script | 30/6/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en SimplePHPscripts GuestBook Script v2.2. Se ha clasificado como problemática. Esto afecta a una parte desconocida del archivo "preview.php" del componente "URL Parameter Handler". La manipulación conduce a Cross-Site Scripting (XSS). Es posible iniciar el ataque de forma remota.… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Event Script | 30/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is some unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. It is recommended to… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Simple Blog | 30/6/2023 | 17/6/2026 | A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. It is… | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can… | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Media (4.8) | 0.37% | — | Simplemodal Contact Form Project Simplemodal Contact Form | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= 1.2.9 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Simple Vimeo Shortcode Project Simple Vimeo Shortcode | 21/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2.9.1 versions. | |
| Modificada | Crítica (9.8) | 0.85% | — | Simple Customer Relationship Management Project Simple Customer Relationship Management | 16/6/2023 | 17/6/2026 | Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Slug Translate Project Simple Slug Translate | 16/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versions. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Ossrs Simple Realtime Server | 12/6/2023 | 17/6/2026 | SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may send a request to the `/api/v1/snapshots` endpoint containing any commands to be… | |
| Modificada | Media (6.1) | 0.47% | — | Simpleredak | 2/6/2023 | 17/6/2026 | eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php. | |
| Modificada | Crítica (9.8) | 0.85% | — | Simpleredak | 2/6/2023 | 17/6/2026 | eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity parameter. | |
| Modificada | Media (6.1) | 0.47% | — | Simpleredak | 2/6/2023 | 17/6/2026 | eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php. | |
| Modificada | Media (5.4) | 0.47% | — | Simpleredak | 1/6/2023 | 17/6/2026 | eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>. | |
| Modificada | Crítica (9.8) | 0.82% | — | Simple Chat System Project Simple Chat System | 31/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=read_msg of the component POST Parameter Handler. The manipulation of the argument convo_id leads to sql injection. The attack… | |
| Modificada | Media (5.9) | 0.57% | — | GO Simple Tunnel Project GO Simple Tunnel | 30/5/2023 | 17/6/2026 | Gost (GO Simple Tunnel) es un túnel simple escrito en golang. Secretos sensibles como contraseñas, tokens y claves API deben ser comparados sólo usando una función de comparación en tiempo constante. La entrada no fiable, procedente de una cabecera HTTP, se compara directamente con un secreto. Como esta comparación no… | |
| Modificada | Alta (8.8) | 0.27% | — | Simplesharebuttons Simple Share Buttons Adder | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions. | |
| Modificada | Media (5.5) | 0.23% | — | Simpledesign Diary With Lock\ | 24/5/2023 | 17/6/2026 | A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the… | |
| Modificada | Alta (8.8) | 0.27% | — | SRS Simple Hits Counter Project SRS Simple Hits Counter | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Atif N SRS Simple Hits Counter plugin <= 1.1.0 versions. | |
| Modificada | Crítica (9.8) | 0.72% | — | Simple Photo Gallery Project Simple Photo Gallery | 17/5/2023 | 17/6/2026 | A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability. | |
| Modificada | Media (4.8) | 0.39% | — | Simple Tooltips Project Simple Tooltips | 12/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Justin Saad Simple Tooltips plugin <= 2.1.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Popup Project Simple Popup | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb ur Rehman Simple PopUp plugin <= 1.8.6 versions. |