Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.47% | — | Simplefilelist Simple File ListAI | 20/6/2026 | 22/6/2026 | The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform… | |
| Aplazada | Alta (7.5) | 0.52% | 💥 PoC | Simplefilelist Simple File ListAI | 20/6/2026 | 22/6/2026 | The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the… | |
| Aplazada | Alta (7.5) | 1.2% | — | Simplefilelist Simple File ListAI | 20/6/2026 | 22/6/2026 | The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead… | |
| Aplazada | Media (5.3) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 18/6/2026 | 18/6/2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by… | |
| Aplazada | Alta (8.1) | 0.46% | — | Really Simple SSLAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Fabian Simple Shopping CartAI | 15/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions. | |
| Aplazada | Media (5.3) | 0.36% | — | Simple Cloudflare TurnstileAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Really Simple SSLAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. | |
| Aplazada | Alta (8.7) | 0.60% | — | Simple-backupAI | 15/6/2026 | 17/6/2026 | WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation using directory… | |
| Analizada | Crítica (9.5) | 5.7% | ⚠ Explotación activa💥 Exploit | Simple-help Simplehelp | 12/6/2026 | 30/6/2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a… | |
| Aplazada | Media (5.1) | 0.24% | — | Quantumcloud Simple Link DirectoryAI | 10/6/2026 | 23/7/2026 | Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser. | |
| Aplazada | Media (5.1) | 0.24% | — | Quantumcloud Simple Link DirectoryAI | 10/6/2026 | 23/7/2026 | Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor. | |
| Aplazada | Alta (8.7) | 0.57% | — | SimplebleAI | 10/6/2026 | 23/7/2026 | SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. There is a stack overflow vulnerability in the dongl backend’s Protocol::simpleble_write function (local, caller-controlled input). A… | |
| Aplazada | Alta (8.6) | 0.62% | — | Simplesamlphp-module-casserverAI | 10/6/2026 | 23/7/2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier.… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Simple Flight Ticket Booking SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (6.4) | 0.33% | — | Simple SEO SlideshowAI | 6/6/2026 | 23/7/2026 | The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.1) | 0.21% | — | Hiweb Migration SimpleAI | 2/6/2026 | 22/7/2026 | The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.5) | 0.39% | — | Really-simple-plugins Really Simple SecurityAI | 2/6/2026 | 22/7/2026 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. | |
| Aplazada | Media (4.4) | 0.18% | — | Simple Custom Login PageAI | 2/6/2026 | 22/7/2026 | The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered… | |
| Aplazada | Alta (7.5) | 0.58% | 💥 PoC | Simple-history Simple HistoryAI | 30/5/2026 | 22/7/2026 | The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as… | |
| Aplazada | Media (6.4) | 0.33% | — | Simple Divi ShortcodeAI | 29/5/2026 | 21/7/2026 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id'… | |
| Aplazada | Media (5.4) | 0.23% | — | Creatorsofcode SimplephpAI | 27/5/2026 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload. | |
| Aplazada | Media (4.3) | 0.18% | — | Search Simple FieldsAI | 27/5/2026 | 17/6/2026 | The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_simple_fields_options() function in functions_admin.php. This makes it possible for unauthenticated attackers to modify the… |