Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 9/9/2026 | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 9/9/2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 10/9/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 4/9/2026 | 4/9/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and… | |
| Aplazada | Media (6.5) | 0.33% | — | TimeticsAI | 3/9/2026 | 3/9/2026 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | |
| Aplazada | Baja (3.8) | 0.22% | — | TimeticsAI | 2/9/2026 | 3/9/2026 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members. | |
| Pendiente de análisis | Crítica (9.9) | 0.29% | — | IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI | 28/8/2026 | 31/8/2026 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | IBM Administration Runtime Expert FOR IAI | 28/8/2026 | 1/9/2026 | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Time4 PopcornAITime4 Popcorn Updater.exeAITime4 Popcorn Pt.upddAI | 27/8/2026 | 1/9/2026 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime. | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Wibu Codemeter RuntimeAI | 27/8/2026 | 1/9/2026 | In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Visitor Traffic Real Time Statistics PROAI | 27/8/2026 | 28/8/2026 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | Hackerbay OneuptimeAI | 26/8/2026 | 16/9/2026 | OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetIsSafe, and the host-literal screening inside… | |
| Aplazada | Alta (7.1) | 0.17% | — | Sublinear-time-solverAIConsciousness-explorerAI | 25/8/2026 | 9/9/2026 | sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools in src/consciousness-explorer/mcp/server.js pass the attacker-controlled filepath… | |
| Aplazada | Alta (8.9) | 1.3% | — | Iptime T24000mAI | 24/8/2026 | 27/8/2026 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Crítica (9.3) | 1.5% | — | EFM Iptime T16000mAI | 24/8/2026 | 24/8/2026 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public… | |
| Aplazada | Baja (2.1) | 0.40% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 23/8/2026 | 26/8/2026 | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 23/8/2026 | 24/8/2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has… |