Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3135▲ 554 respecto a la semana anterior
Críticas / altas1494▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%💥 ExploitCmsmadesimple CMS Made Simple27/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaBaja (2.1)0.44%—Simplecdr-x21/9/200516/6/2026
The MasterDataCD::createImage function in masterdatacd.cpp for SimpleCDR-X 1.3.3 creates the .temp temporary directory with insecure permissions, which allows local users to read sensitive ISO images.
ModificadaAlta (7.5)6.8%💥 ExploitCmsmadesimple CMS Made Simple8/9/200516/6/2026
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.
ModificadaMedia (5)1.5%—Simple Machines Forum7/9/200516/6/2026
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
ModificadaMedia (5)5.6%💥 ExploitAlexander Palmo Simple PHP Blog2/9/200516/6/2026
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
ModificadaAlta (7.5)4.3%—Simpleproxy2/9/200516/6/2026
Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.
ModificadaAlta (7.5)51%💥 ExploitAlexander Palmo Simple PHP Blog30/8/200516/6/2026
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
ModificadaMedia (4.3)1.4%—Cmsmadesimple CMS Made Simple27/7/200516/6/2026
Vulnerabilidad de secuencia de comandos en sitios cruzados en index.php para CMSSimple 2.4 y anteriores permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "search" en la función de búsqueda.
ModificadaMedia (4.3)1.4%—Simple Message BoardAI19/7/200516/6/2026
Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados en Simple Message Board Version 2.0 Beta 1 permite que atacantes remtos inyecten script web arbitrario o HTML mediante 1) el parámetro FID en "forum.cfm", 2) el parámetro UID en "user.cfm", 3) el parámetro TID en "thread.cfm" o 4) el parámetro…
ModificadaMedia (5)4.1%💥 ExploitAlexander Palmo Simple PHP Blog11/7/200516/6/2026
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
ModificadaMedia (5)3.1%💥 ExploitDead Pirate Software Simplecam11/5/200516/6/2026
Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.
ModificadaAlta (7.5)9.7%💥 ExploitPmsoftware Simple WEB Server2/5/200516/6/2026
Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.
ModificadaMedia (4.3)1.7%💥 ExploitAlexander Palmo Simple PHP Blog2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (5)1.7%—Alexander Palmo Simple PHP Blog2/5/200516/6/2026
Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.
ModificadaMedia (5)1.3%—Alexander Palmo Simple PHP Blog2/5/200516/6/2026
Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.
ModificadaAlta (7.5)1.5%—Sysbotz SimpledataAI31/12/200416/6/2026
Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.
ModificadaMedia (4.3)1.7%💥 ExploitSimple Machines SMF5/5/200416/6/2026
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.
ModificadaMedia (4.3)2.1%💥 ExploitSimple Machines SMFYabb15/3/200416/6/2026
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
ModificadaMedia (5)1.5%—KAI Blankenhorn Bitfolge Simple AND Nice Index File31/12/200316/6/2026
Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.
ModificadaMedia (4.3)1.1%—Onedotoh Simple File Manager31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.
ModificadaMedia (4.3)0.85%—KAI Blankenhorn Bitfolge Simple AND Nice Index File31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)3.9%—Telcondex Simplewebserver29/10/200316/6/2026
Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.
ModificadaAlta (7.5)2.3%💥 ExploitMysimplenews31/12/200216/6/2026
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
ModificadaMedia (5)1.6%—SWS Simple WEB Server31/12/200216/6/2026
Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist.
ModificadaMedia (5)3.2%💥 ExploitTelcondex Simplewebserver31/12/200216/6/2026
TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
Orbitaley — Vulnerabilidades