Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3135▲ 554 respecto a la semana anterior
Críticas / altas1494▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Cmsmadesimple CMS Made Simple | 27/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Baja (2.1) | 0.44% | — | Simplecdr-x | 21/9/2005 | 16/6/2026 | The MasterDataCD::createImage function in masterdatacd.cpp for SimpleCDR-X 1.3.3 creates the .temp temporary directory with insecure permissions, which allows local users to read sensitive ISO images. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Cmsmadesimple CMS Made Simple | 8/9/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter. | |
| Modificada | Media (5) | 1.5% | — | Simple Machines Forum | 7/9/2005 | 16/6/2026 | Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server. | |
| Modificada | Media (5) | 5.6% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 2/9/2005 | 16/6/2026 | comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter. | |
| Modificada | Alta (7.5) | 4.3% | — | Simpleproxy | 2/9/2005 | 16/6/2026 | Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply. | |
| Modificada | Alta (7.5) | 51% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 30/8/2005 | 16/6/2026 | upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code. | |
| Modificada | Media (4.3) | 1.4% | — | Cmsmadesimple CMS Made Simple | 27/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en index.php para CMSSimple 2.4 y anteriores permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "search" en la función de búsqueda. | |
| Modificada | Media (4.3) | 1.4% | — | Simple Message BoardAI | 19/7/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados en Simple Message Board Version 2.0 Beta 1 permite que atacantes remtos inyecten script web arbitrario o HTML mediante 1) el parámetro FID en "forum.cfm", 2) el parámetro UID en "user.cfm", 3) el parámetro TID en "thread.cfm" o 4) el parámetro… | |
| Modificada | Media (5) | 4.1% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 11/7/2005 | 16/6/2026 | SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Dead Pirate Software Simplecam | 11/5/2005 | 16/6/2026 | Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Pmsoftware Simple WEB Server | 2/5/2005 | 16/6/2026 | Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.7% | — | Alexander Palmo Simple PHP Blog | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter. | |
| Modificada | Media (5) | 1.3% | — | Alexander Palmo Simple PHP Blog | 2/5/2005 | 16/6/2026 | Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Sysbotz SimpledataAI | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Simple Machines SMF | 5/5/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Simple Machines SMFYabb | 15/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags. | |
| Modificada | Media (5) | 1.5% | — | KAI Blankenhorn Bitfolge Simple AND Nice Index File | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory. | |
| Modificada | Media (4.3) | 1.1% | — | Onedotoh Simple File Manager | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names. | |
| Modificada | Media (4.3) | 0.85% | — | KAI Blankenhorn Bitfolge Simple AND Nice Index File | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.9% | — | Telcondex Simplewebserver | 29/10/2003 | 16/6/2026 | Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Mysimplenews | 31/12/2002 | 16/6/2026 | Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3. | |
| Modificada | Media (5) | 1.6% | — | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Telcondex Simplewebserver | 31/12/2002 | 16/6/2026 | TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. |