Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
2143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Usbmemorydirect Simple Custom Author Profiles | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | WP Simple Events Project WP Simple Events | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions. | |
| Modificada | Alta (8.8) | 1.3% | — | Cmsmadesimple CMS Made Simple | 8/5/2023 | 17/6/2026 | SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Cmsmadesimple CMS Made Simple | 8/5/2023 | 17/6/2026 | File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file. | |
| Modificada | Media (5.4) | 0.36% | — | Simple Youtube Responsive Project Simple Youtube Responsive | 4/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Portfolio Gallery Project Simple Portfolio Gallery | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions. | |
| Modificada | Media (4.8) | 0.56% | — | Simple Student Information System Project Simple Student Information System | 29/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Student Information System 1.0. It has been classified as problematic. This affects an unknown part of the file /classes/Master.php?f=save_course of the component Add New Course. The manipulation of the argument name with the input… | |
| Modificada | Media (4.8) | 0.58% | — | Simple Mobile Comparison Website Project Simple Mobile Comparison Website | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack may be initiated… | |
| Modificada | Media (4.8) | 0.37% | — | Simple Yearly Archive Project Simple Yearly Archive | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Simple PDF Viewer Project Simple PDF Viewer | 23/4/2023 | 17/6/2026 | Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Ibenic Simple Giveaways | 10/4/2023 | 17/6/2026 | The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.44% | — | Ibenic Simple Giveaways | 10/4/2023 | 17/6/2026 | The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.44% | — | Ibenic Simple Giveaways | 10/4/2023 | 17/6/2026 | The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 0.82% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 7/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The… | |
| Modificada | Crítica (9.1) | 0.64% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 7/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This vulnerability affects unknown code of the file delete_user_query.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.38% | — | Implecode Product Catalog Simple | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions. | |
| Modificada | Media (6.1) | 0.36% | — | Simple Guestbook Management System Project Simple Guestbook Management System | 6/4/2023 | 9/7/2026 | Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments. | |
| Modificada | Alta (8.8) | 0.26% | — | Hasthemes Really Simple Google TAG Manager | 6/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | Simple Mobile Comparison Website Project Simple Mobile Comparison Website | 6/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to… | |
| Modificada | Media (5.4) | 0.39% | — | Simple Staff List Project Simple Staff List | 4/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.2 versions. | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple Mobile Comparison Website Project Simple Mobile Comparison Website | 2/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/fields/manage_field.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may… | |
| Modificada | Crítica (9.8) | 0.61% | — | Simple Task Allocation System Project Simple Task Allocation System | 2/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Task Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.64% | — | Simple Task Allocation System Project Simple Task Allocation System | 1/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 30/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (4.8) | 0.42% | — | Mrdigital Simple Image Popup | 29/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions. |