Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.24% | — | Kodeshpa SimplifiedAI | 14/8/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified simplified allows Server Side Request Forgery.This issue affects Simplified: from n/a through <= 1.0.11. | |
| Aplazada | Crítica (10) | 0.96% | — | Kodeshpa SimplifiedAI | 18/2/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simplified: from n/a through <= 1.0.6. | |
| Modificada | Media (6.1) | 0.56% | — | Mysimplifiedsql Project Mysimplifiedsql | 7/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in foxoverflow MySimplifiedSQL. This issue affects some unknown processing of the file MySimplifiedSQL_Examples.php. The manipulation of the argument FirstName/LastName leads to cross site scripting. The attack may be initiated remotely. The patch is… | |
| Modificada | Crítica (9.8) | 2.3% | — | Ontraport Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ontraport Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function. | |
| Modificada | Crítica (9.8) | 17% | — | Membership Simplified Project Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges. | |
| Modificada | Media (6.1) | 2.2% | — | Oxil Simplified-content | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin simplified-content v1.0.0 | |
| Modificada | Media (5.4) | 0.27% | — | Bouqs - Flowers Simplified Project Bouqs - Flowers Simplified | 20/10/2014 | 17/6/2026 | The Bouqs - Flowers Simplified (aka com.bouqs.activity) application 1.8.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |