Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.26% | — | Simplejobscript | 4/3/2026 | 17/6/2026 | Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal… | |
| Analizada | Alta (8.8) | 0.35% | — | Simplejobscript | 4/3/2026 | 17/6/2026 | Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attackers can send POST requests to delete_application_ajax.php with crafted payloads to extract sensitive data, bypass authentication, or modify… | |
| Analizada | Alta (8.8) | 0.30% | — | Simplejobscript | 4/3/2026 | 17/6/2026 | Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid parameter. Attackers can send POST requests to the register-recruiters endpoint with time-based SQL injection payloads to extract sensitive data or… | |
| Analizada | Alta (8.8) | 0.46% | — | Simplejobscript | 4/3/2026 | 17/6/2026 | Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive… | |
| Analizada | Alta (8.8) | 0.37% | — | Simplejobscript | 4/3/2026 | 17/6/2026 | Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract… | |
| Modificada | Crítica (9.8) | 1.8% | — | Simplejobscript | 7/2/2020 | 17/6/2026 | An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php. | |
| Modificada | Crítica (9.8) | 2.8% | — | Simplejobscript | 31/1/2020 | 17/6/2026 | controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume. | |
| Modificada | Crítica (9.8) | 1.5% | — | Simplejobscript | 21/1/2020 | 17/6/2026 | An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Typo3 BB Simplejobs | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Zeeways Zeejobsite | 12/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (6.5) | 3.3% | — | Zeeways Zeejobsite | 7/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/. | |
| Modificada | Alta (7.5) | 1.0% | — | Zeeways Zeejobsite | 19/8/2008 | 16/6/2026 | SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Enthrallweb Ejobs | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter. |