Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

2142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%—Simplefilelist Simple File ListAI20/6/202622/6/2026
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform…
AplazadaAlta (7.5)0.52%💥 PoCSimplefilelist Simple File ListAI20/6/202622/6/2026
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the…
AplazadaAlta (7.5)1.2%—Simplefilelist Simple File ListAI20/6/202622/6/2026
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead…
AplazadaMedia (5.3)0.35%—Simple-membership-plugin Simple MembershipAI18/6/202618/6/2026
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by…
AplazadaAlta (8.1)0.46%—Really Simple SSLAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
AplazadaAlta (7.5)0.39%—Fabian Simple Shopping CartAI15/6/202617/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
AplazadaMedia (6.5)0.22%—Simple-membership-plugin Simple MembershipAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.
AplazadaMedia (5.3)0.36%—Simple Cloudflare TurnstileAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
AplazadaAlta (7.5)0.35%—Simple-membership-plugin Simple MembershipAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
AplazadaMedia (6.5)0.30%—Really Simple SSLAI15/6/202617/6/2026
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
AplazadaAlta (8.7)0.60%—Simple-backupAI15/6/202617/6/2026
WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation using directory…
AnalizadaCrítica (9.5)5.7%⚠ Explotación activa💥 ExploitSimple-help Simplehelp12/6/202630/6/2026
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a…
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.
AplazadaAlta (8.7)0.57%—SimplebleAI10/6/202623/7/2026
SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. There is a stack overflow vulnerability in the dongl backend’s Protocol::simpleble_write function (local, caller-controlled input). A…
AplazadaAlta (8.6)0.62%—Simplesamlphp-module-casserverAI10/6/202623/7/2026
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier.…
AplazadaMedia (5.5)0.27%—Code-projects Simple Flight Ticket Booking SystemAI8/6/202623/7/2026
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaMedia (6.4)0.33%—Simple SEO SlideshowAI6/6/202623/7/2026
The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaMedia (6.1)0.21%—Hiweb Migration SimpleAI2/6/202622/7/2026
The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaAlta (7.5)0.39%—Really-simple-plugins Really Simple SecurityAI2/6/202622/7/2026
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge.
AplazadaMedia (4.4)0.18%—Simple Custom Login PageAI2/6/202622/7/2026
The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered…
AplazadaAlta (7.5)0.58%💥 PoCSimple-history Simple HistoryAI30/5/202622/7/2026
The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as…
AplazadaMedia (6.4)0.33%—Simple Divi ShortcodeAI29/5/202621/7/2026
The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id'…
AplazadaMedia (5.4)0.23%—Creatorsofcode SimplephpAI27/5/20265/7/2026
A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.
AplazadaMedia (4.3)0.18%—Search Simple FieldsAI27/5/202617/6/2026
The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_simple_fields_options() function in functions_admin.php. This makes it possible for unauthenticated attackers to modify the…
Orbitaley — Vulnerabilidades