Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
5652 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 30/8/2026 | 31/8/2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 30/8/2026 | 31/8/2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 29/8/2026 | 31/8/2026 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 29/8/2026 | 31/8/2026 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (4.1) | 0.31% | — | Smackcoders WP Ultimate CSV ImporterAI | 29/8/2026 | 31/8/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | |
| Aplazada | Alta (8.2) | 0.32% | — | Codesmiths User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other… | |
| Aplazada | Media (5.5) | 0.41% | — | Ericsson CodecheckerAI | 28/8/2026 | 1/9/2026 | CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte… | |
| Aplazada | Baja (2) | 0.17% | — | Ericsson CodecheckerAI | 28/8/2026 | 1/9/2026 | CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size passed down is the full PATH_MAX. safe_strcpy() is strncpy(), which NUL-pads the… | |
| Aplazada | Baja (2.1) | 0.49% | — | Roocodeinc Roo-codeAI | 28/8/2026 | 28/8/2026 | A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/tools/ApplyPatchTool.ts of the component ApplyPatchTool. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used.… | |
| Aplazada | Baja (2.9) | 0.28% | — | Roocode ROO CodeAI | 28/8/2026 | 31/8/2026 | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack may be performed from remote. A high… | |
| Aplazada | Baja (2) | 0.30% | — | Rootcodeinc Roo-codeAI | 28/8/2026 | 28/8/2026 | A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Crítica (9.8) | 0.60% | — | YU AI Code MotherAI | 28/8/2026 | 9/9/2026 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root. | |
| Analizada | Media (6.8) | 0.20% | — | Amazon Diagram-as-code | 27/8/2026 | 4/9/2026 | A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform… | |
| Aplazada | Baja (2.1) | 0.40% | — | Roocode ROO CodeAI | 27/8/2026 | 28/8/2026 | A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection. The attack can be executed remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2) | 0.30% | — | Roocodeinc Roo-codeAI | 27/8/2026 | 31/8/2026 | A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of the component CodeIndexManager. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime. | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are… | |
| Aplazada | Alta (8.8) | 0.51% | — | Code4recovery 12 Step Meeting ListAI | 27/8/2026 | 28/8/2026 | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as… | |
| Aplazada | Media (6.9) | 0.41% | — | Ezcode Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 26/8/2026 | 29/8/2026 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.69% | — | Itsourcecode Payroll SystemAI | 26/8/2026 | 28/8/2026 | A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit… | |
| Aplazada | Media (5.4) | 0.45% | — | Starlette AdminAITiangolo FastapiAIEncode StarletteAI | 26/8/2026 | 9/9/2026 | Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An… |