Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

2142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.41%—Sourcecodester Simple POS AND Inventory SystemAI25/5/202623/7/2026
A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Name results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and…
AplazadaBaja (2)0.33%—Sourcecodester Simple POS AND Inventory SystemAI25/5/202623/7/2026
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may…
AplazadaBaja (2.1)0.35%—Sourcecodester Simple POS AND Inventory SystemAI25/5/202620/7/2026
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…
AplazadaBaja (2)0.33%—Sourcecodester Simple POS AND Inventory SystemAI25/5/202623/7/2026
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now…
AnalizadaMedia (5.1)0.32%—Simple Hierarchical Select Project Simple Hierarchical Select21/5/202623/7/2026
Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can…
AnalizadaMedia (6.1)0.27%—Simplesamlphp-module-casserver18/5/20267/10/2026
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or…
AplazadaMedia (6.9)0.53%—Simple FieldsAI17/5/202617/6/2026
Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_fields.php to…
AplazadaMedia (5.1)0.24%—Cmsmadesimple CMS Made SimpleAI16/5/202629/9/2026
CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other authenticated users…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaCrítica (9.1)0.21%—Amazon Simple Notification ServiceAIUseplunk PlunkAI8/5/202617/6/2026
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verifying the SNS signature, certificate, or topic ARN, meaning anyone can forge a valid-looking webhook request. This allows…
AplazadaBaja (2.1)0.32%—Code-projects Simple Chat SystemAI8/5/202617/6/2026
A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipulation of the argument type/length/business parameter validity results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaMedia (6.4)0.32%—Simple OWL ShortcodesAI5/5/202617/6/2026
The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of the 'owls_wrapper' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.35%—Quantumcloud Simple Link DirectoryAI2/5/202617/6/2026
The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it…
AplazadaMedia (5.5)0.59%—Getsimpletool Mcpo-simple-serverAI29/4/202617/6/2026
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It is possible to initiate the attack…
AplazadaAlta (7.6)0.38%—Steve Burge Simple-tagsAITaxopressAI29/4/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0.
AplazadaMedia (5.3)0.44%—Really-simple-plugins ComplianzAI29/4/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any…
AplazadaMedia (5.5)2.1%—Choieastsea Simple Openstack MCPAI27/4/202617/6/2026
A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and…
ModificadaAlta (8.2)1.0%💥 PoCSimple-git Project Simple-git25/4/202615/7/2026
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed…
AplazadaMedia (6.4)0.32%—Simple Random Posts ShortcodeAI22/4/202617/6/2026
The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the 'simple_random_posts' shortcode in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This…
AplazadaCrítica (9.8)0.80%💥 PoCCodeastro Simple Attendance Management SystemAI17/4/202617/6/2026
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
AplazadaCrítica (9.8)0.47%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.
AplazadaCrítica (9.8)0.47%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.
AplazadaCrítica (9.4)0.41%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.