Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.91% | — | SimplechatAI | 16/7/2026 | 16/7/2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied… | |
| Aplazada | Media (6.3) | 0.44% | — | Simplemachines ForumAI | 14/7/2026 | 15/7/2026 | Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 14/7/2026 | 15/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud Simple Business Directory PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Simplefilelist Simple File ListAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8. | |
| Aplazada | Baja (2.1) | 0.33% | — | Coderastro Simple Online Leave Management SystemAI | 13/7/2026 | 14/7/2026 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Alta (8.8) | 0.74% | — | Simple JWT LoginAI | 11/7/2026 | 13/7/2026 | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT… | |
| Aplazada | Alta (7.1) | 0.47% | — | Simplemachines ForumAI | 10/7/2026 | 14/7/2026 | Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 9/7/2026 | 9/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Simple Online Leave Management SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (4.9) | 0.50% | — | FaissAIFlowise SimplestoreAIFlowiseai FlowiseAI | 8/7/2026 | 9/7/2026 | Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations, potentially enabling code execution or… | |
| Aplazada | Crítica (9.1) | 1.2% | — | Simple Coherent FormAI | 8/7/2026 | 8/7/2026 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily… | |
| Aplazada | Alta (8.8) | 0.51% | — | Simple-membership-plugin Simple MembershipAI | 6/7/2026 | 6/7/2026 | The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdeletequery.php. Such manipulation of the argument user_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument user_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Media (5.9) | 0.24% | — | Getlasso Simple UrlsAI | 2/7/2026 | 2/7/2026 | Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Quantumcloud Simple Link DirectoryAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | |
| Aplazada | Media (5.5) | 0.51% | — | Sourcecodester Simple Food Ordering SystemAI | 29/6/2026 | 29/6/2026 | A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used. | |
| Aplazada | Media (4.3) | 0.29% | — | Matteo Manna Simple User AvatarAI | 29/6/2026 | 8/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simple PAY WordpressAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpkube Simple Basic Contact FormAI | 23/6/2026 | 23/6/2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or… | |
| Aplazada | Media (6.5) | 0.47% | — | Simplefilelist Simple File ListAI | 20/6/2026 | 22/6/2026 | The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform… |