Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
2143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.56% | — | Really-simple-plugins Complianz | 27/3/2023 | 17/6/2026 | The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | |
| Modificada | Media (4.8) | 0.44% | — | Simplefilelist Simple File List | 27/3/2023 | 17/6/2026 | The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.39% | — | Very Simple Google Maps Project Very Simple Google Maps | 23/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions. | |
| Modificada | Crítica (9.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 23/3/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function. | |
| Modificada | Crítica (9.8) | 0.77% | — | Fabian Simple Online Hotel Reservation System | 22/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file add_room.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-223554 is the identifier assigned to this… | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 22/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (8.1) | 0.61% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. This vulnerability affects unknown code. The manipulation of the argument email/password with the input test1%40test.com ' AND (SELECT 6077 FROM (SELECT(SLEEP(5)))dltn) AND 'PhRa'='PhRa leads to sql injection.… | |
| Modificada | Alta (8.1) | 0.61% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file admin/admin_index.php. The manipulation of the argument username/password with the input admin' AND (SELECT 8062 FROM (SELECT(SLEEP(5)))meUD)-- hLiX leads to sql… | |
| Modificada | Alta (8.1) | 0.61% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file function/edit_customer.php. The manipulation of the argument firstname/mi/lastname with the input a' RLIKE SLEEP(5) AND 'dAbu'='dAbu leads… | |
| Modificada | Media (6.1) | 0.52% | — | Code-projects Simple ART Gallery | 19/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Simple Art Gallery 1.0. Affected by this issue is some unknown functionality of the file adminHome.php. The manipulation of the argument about_info leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.73% | — | Code-projects Simple ART Gallery | 19/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Art Gallery 1.0. Affected by this vulnerability is an unknown functionality of the file adminHome.php. The manipulation of the argument reach_city leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.72% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 19/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.75% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 19/3/2023 | 17/6/2026 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. | |
| Modificada | Crítica (9.8) | 0.87% | — | Simple Music Player Project Simple Music Player | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown function of the file save_music.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 2.0% | — | Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP | 16/3/2023 | 17/6/2026 | Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. | |
| Modificada | Media (5.3) | 0.55% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 16/3/2023 | 17/6/2026 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it… | |
| Modificada | Crítica (9.8) | 0.76% | — | Code-projects Simple ART Gallery | 15/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the file adminHome.php. The manipulation of the argument social_facebook leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 1.0% | — | Code-projects Simple ART Gallery | 15/3/2023 | 17/6/2026 | A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the function sliderPicSubmit of the file adminHome.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-223126 is the identifier assigned to this vulnerability. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 15/3/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 15/3/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 15/3/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 15/3/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 15/3/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function. | |
| Modificada | Crítica (9.8) | 0.55% | — | Simple Bakery Shop Management System Project Simple Bakery Shop Management System | 12/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Bakery Shop Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation of the argument username/password with the input admin' or 1=1 -- leads to sql injection. The… | |
| Modificada | Media (4.8) | 0.59% | — | Simple Payroll System With Dynamic TAX Bracket Project Simple Payroll System With Dynamic TAX Bracket | 1/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The… |