Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
2143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 27/2/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 27/2/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 27/2/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 27/2/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function. | |
| Modificada | Media (5.4) | 0.56% | — | Oretnom23 Simple Customer Relationship Management System | 27/2/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page. | |
| Modificada | Alta (8.8) | 1.0% | — | Oretnom23 Simple Customer Relationship Management System | 27/2/2023 | 17/6/2026 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel. | |
| Modificada | Media (6.1) | 0.54% | — | Oretnom23 Simple Responsive Tourism Website | 26/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Responsive Tourism Website 1.0. This affects an unknown part of the file /tourism/rate_review.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to… | |
| Modificada | Media (5.3) | 0.91% | — | Alphaware Simple E-commerce System Project Alphaware Simple E-commerce System | 24/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access controls. It is possible to initiate the… | |
| Modificada | Media (5.4) | 0.63% | — | Simple File Downloader Project Simple File Downloader | 21/2/2023 | 17/6/2026 | The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Crítica (9.8) | 0.93% | — | Oretnom23 Simple Customer Relationship Management System | 19/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management System 1.0. This affects an unknown part of the file /php-scrm/login.php. The manipulation of the argument Password leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Modificada | Media (5.4) | 2.7% | 💥 Exploit | Simple Food Ordering System Project Simple Food Ordering System | 18/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file process_order.php. The manipulation of the argument order leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Simple Task Managing System Project Simple Task Managing System | 17/2/2023 | 17/6/2026 | Vulnerabilidad de inyección SQL en Simple Task Management System versión 1.0 en login.php en los parámetros 'username' y 'password', permite a los atacantes ejecutar código arbitrario y obtener información confidencial. | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Getlasso Simple Urls | 13/2/2023 | 17/6/2026 | The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (8.8) | 0.94% | — | Getlasso Simple Urls | 13/2/2023 | 17/6/2026 | The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber. | |
| Modificada | Alta (7.5) | 0.94% | — | Khanacademy Simple-markdown | 12/2/2023 | 17/6/2026 | A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file simple-markdown.js. The manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. Upgrading to version 0.5.2 is able… | |
| Modificada | Alta (7.5) | 1.1% | — | Khanacademy Simple-markdown | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The… | |
| Modificada | Media (6.1) | 0.53% | — | Simple Sales Management System Project Simple Sales Management System | 7/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 sales management system 1.0, allows attackers to execute arbitrary code via the product_name and product_price inputs in file print.php. | |
| Modificada | Media (5.4) | 0.60% | — | Simple Tooltips Project Simple Tooltips | 6/2/2023 | 17/6/2026 | The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.52% | — | Simple Sitemap Project Simple Sitemap | 30/1/2023 | 17/6/2026 | El complemento Simple Sitemap de WordPress anterior a 3.5.8 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían usarse contra usuarios… | |
| Modificada | Crítica (9.8) | 2.7% | — | Simple-git Project Simple-git | 26/1/2023 | 17/6/2026 | Las versiones del paquete simple-git anteriores a la 3.16.0 son vulnerables a la ejecución remota de código (RCE) a través de los métodos clone(), pull(), push() y listRemote(), debido a una sanitización de entrada inadecuada. Esta vulnerabilidad existe debido a una solución incompleta de… | |
| Modificada | Media (5.4) | 0.53% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 23/1/2023 | 17/6/2026 | El complemento Simple Shopping Cart de WordPress anterior a 4.6.2 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como el de colaborador realizar ataques de cross-site scripting almacenado que podrían utilizarse… | |
| Modificada | Media (5.4) | 0.56% | — | Simplesamlphp-module-openidprovider | 17/1/2023 | 16/6/2026 | ** NO SOPORTADO CUANDO SE ASIGNÓ ** Se encontró una vulnerabilidad en simplesamlphp simplesamlphp-module-openidprovider hasta 0.8.x. Ha sido declarada problemática. Una función desconocida del archivo templates/trust.tpl.php es afectada por esta vulnerabilidad. La manipulación del argumento StateID conduce a… | |
| Modificada | Media (5.4) | 0.53% | — | Castos Seriously Simple Podcasting | 16/1/2023 | 17/6/2026 | El complemento Seriously Simple Podcasting de WordPress anterior a 2.19.1 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían ser… | |
| Modificada | Media (5.4) | 0.53% | — | Simple-membership-plugin Simple Membership | 16/1/2023 | 17/6/2026 | El complemento Simple Membership de WordPress en las versiones anteriores a la 4.2.2 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de Cross-Site Scripting almacenado contra… | |
| Modificada | Alta (7.5) | 1.3% | — | Libsdl Simple Directmedia LayerRedhat Enterprise Linux | 12/1/2023 | 17/6/2026 | Se descubrió un posible problema de pérdida de memoria en SDL2 en la función GLES_CreateTexture() en SDL_render_gles.c. La vulnerabilidad permite a un atacante provocar un ataque de denegación de servicio. La vulnerabilidad afecta a SDL2 v2.0.4 y superiores. SDL-1.x no se ve afectado. |