Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
5662 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Food Order SystemAI | 15/8/2026 | 20/8/2026 | A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online Food Order SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.53% | — | Sourcecodester Online Clothing StoreAI | 15/8/2026 | 20/8/2026 | A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 15/8/2026 | 20/8/2026 | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewmedicine.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (4.3) | 0.25% | — | EC ShortcodesAI | 15/8/2026 | 26/8/2026 | The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Simple Doctors Appointment SystemAI | 14/8/2026 | 18/8/2026 | A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Client Management SystemAI | 14/8/2026 | 14/8/2026 | A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester AIR Cargo Management SystemAI | 14/8/2026 | 14/8/2026 | A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 14/8/2026 | 14/8/2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Student Information SystemAI | 13/8/2026 | 14/8/2026 | A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Network-ai ClaudehookbridgeAIAnthropic Claude CodeAI | 13/8/2026 | 9/9/2026 | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Anthropic Claude Code TemplatesAI | 11/8/2026 | 9/9/2026 | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute… | |
| Pendiente de análisis | Alta (7.9) | 0.19% | — | TCG TPM 2.0 Reference CodeAI | 11/8/2026 | 8/9/2026 | An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with… | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio Code | 11/8/2026 | 24/9/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Doctors Appointment SystemAI | 10/8/2026 | 12/8/2026 | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to… |