Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.24%—Kodeshpa SimplifiedAI14/8/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified simplified allows Server Side Request Forgery.This issue affects Simplified: from n/a through <= 1.0.11.
AplazadaCrítica (10)0.96%—Kodeshpa SimplifiedAI18/2/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simplified: from n/a through <= 1.0.6.
ModificadaMedia (6.1)0.56%—Mysimplifiedsql Project Mysimplifiedsql7/1/202317/6/2026
A vulnerability, which was classified as problematic, has been found in foxoverflow MySimplifiedSQL. This issue affects some unknown processing of the file MySimplifiedSQL_Examples.php. The manipulation of the argument FirstName/LastName leads to cross site scripting. The attack may be initiated remotely. The patch is…
ModificadaCrítica (9.8)2.3%—Ontraport Membership Simplified14/9/201717/6/2026
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.
ModificadaCrítica (9.8)2.3%—Ontraport Membership Simplified14/9/201717/6/2026
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.
ModificadaCrítica (9.8)17%—Membership Simplified Project Membership Simplified14/9/201717/6/2026
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
ModificadaMedia (6.1)2.2%—Oxil Simplified-content10/10/201617/6/2026
Reflected XSS in wordpress plugin simplified-content v1.0.0
ModificadaMedia (5.4)0.27%—Bouqs - Flowers Simplified Project Bouqs - Flowers Simplified20/10/201417/6/2026
The Bouqs - Flowers Simplified (aka com.bouqs.activity) application 1.8.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.