Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.47% | — | Wecodex Restaurant CMS | 26/3/2026 | 17/6/2026 | Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind… | |
| Analizada | Alta (8.8) | 0.52% | — | Wecodex Shipping System CMS | 26/3/2026 | 17/6/2026 | Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login endpoint to… | |
| Aplazada | Media (6.5) | 0.16% | — | Codexthemes Thegem Theme ElementsAI | 6/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements allows DOM-Based XSS.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.11.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Codexthemes Thegem Theme Elements FOR ElementorAI | 6/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows Stored XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Codexthemes Thegem Theme Elements ElementorAI | 6/1/2026 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0. | |
| Aplazada | Media (5.4) | 0.20% | — | Codexthemes Thegem ElementorAICodexthemes Thegem WpbakeryAI | 30/12/2025 | 17/6/2026 | Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1. | |
| Aplazada | Alta (7.5) | 0.38% | — | Codexthemes Thegem Elements ElementorAI | 23/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1. | |
| Aplazada | Media (6.5) | 0.16% | — | Codexthemes Thegem Theme Elements FOR ElementorAI | 23/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1. | |
| Aplazada | Media (4.3) | 0.22% | — | Codexpert INC Restrict Elementor WidgetsAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and Sections restrict-elementor-widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Elementor Widgets, Columns and Sections: from n/a through <= 1.12. | |
| Aplazada | Alta (8.1) | 0.50% | — | Codexthemes Thegem Theme ElementsAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Codexthemes Thegem Theme ElementsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Codex-themes ThegemAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Codexthemes Thegem ElementorAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5. | |
| Aplazada | Media (6.5) | 0.20% | — | Codex-themes ThegemAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5. | |
| Aplazada | Alta (8.5) | 0.31% | — | Codexpert Coschool LMSAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codexpert, Inc CoSchool LMS coschool allows Blind SQL Injection.This issue affects CoSchool LMS: from n/a through <= 1.4.3. | |
| Aplazada | Media (6.5) | 0.34% | — | Codexthemes Thegem Demo ImportAI | 6/11/2025 | 5/10/2026 | Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects TheGem Demo Import (for WPBakery): from n/a through <= 5.10.5. | |
| Aplazada | Media (5.4) | 0.27% | — | Codex-themes ThegemAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem: from n/a through <= 5.10.5. | |
| Aplazada | Media (5.4) | 0.27% | — | Codex-themes ThegemAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem (Elementor): from n/a through <= 5.10.5. | |
| Aplazada | Alta (8.6) | 0.87% | — | Openai Codex CLIAIOpenai Codex IDE ExtensionAI | 22/9/2025 | 17/6/2026 | Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the… | |
| Aplazada | Media (4.3) | 0.25% | — | Codexpert INC CF7 SubmissionsAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Codexpert, Inc CF7 Submissions cf7-submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Submissions: from n/a through <= 0.26. | |
| Aplazada | Media (4.3) | 0.44% | — | Codexpert CodesignerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Codexpert, Inc CoDesigner woolementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoDesigner: from n/a through <= 4.29. | |
| Aplazada | Alta (8.8) | 0.84% | — | Codex CLIAI | 13/8/2025 | 17/6/2026 | Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory. | |
| Aplazada | Media (4.1) | 0.19% | — | Openai Codex CLIAIRipgrepAI | 25/7/2025 | 17/6/2026 | OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Codexpert INC Coschool LMSAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This issue affects CoSchool LMS: from n/a through <= 1.4.3. | |
| Aplazada | Alta (8.8) | 0.45% | — | Codexpert WC AffiliateAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16. |