Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

5663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI6/8/202612/8/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the…
AplazadaMedia (5.3)0.37%—Sourcecodester Online Examination AND Learning Management SystemAI6/8/202612/8/2026
A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely.
AplazadaMedia (5.3)0.35%—Sourcecodester Online Examination & Learning Management SystemAI6/8/202612/8/2026
A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely.
AplazadaMedia (5.3)0.37%—Sourcecodester Online Examination AND Learning Management SystemAI6/8/202612/8/2026
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.
AplazadaMedia (5.9)0.16%—Ayecode GetpaidAI6/8/202626/8/2026
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.
AplazadaAlta (7.1)0.25%—Wpide File Manager AND Code EditorAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
AplazadaMedia (6.5)0.22%—Codesupplyco PowerkitAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
AplazadaAlta (7.1)0.25%—Code-atlantic Popup MakerAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
AplazadaAlta (7.1)0.13%—Data443 Tracking Code ManagerAI6/8/202612/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
AplazadaMedia (6.4)0.26%—Ayecode UserswpAI6/8/202612/8/2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (5.5)0.43%—Sourcecodester Computer Repair Shop Management SystemAI6/8/202612/8/2026
A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI6/8/202612/8/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation of the argument editid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to…
AplazadaCrítica (9.1)0.49%—Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI6/8/202626/8/2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy…
Pendiente de análisisMedia (4.3)0.27%—Jenkins AWS Codebuild PluginAI5/8/202631/8/2026
Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Pendiente de análisisMedia (4.3)0.27%—Jenkins Codesonar PluginAI5/8/202631/8/2026
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AplazadaCrítica (9.3)0.84%—Opencode StudioAI4/8/202616/9/2026
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate…
Pendiente de análisisMedia (6.2)0.15%—Wellbia Xigncode3AI3/8/20263/8/2026
Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.
AplazadaCrítica (9.1)0.40%—Codection Import AND Export Users AND CustomersAI3/8/202626/8/2026
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or…
AplazadaMedia (4.9)0.47%—Codection Import AND Export Users AND CustomersAI3/8/202629/9/2026
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
AplazadaMedia (6.6)1.2%—Ayecode GetpaidAI1/8/202612/8/2026
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to…
AplazadaMedia (6.4)0.35%—Codesupplyco PowerkitAI1/8/202612/8/2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (6.4)0.36%—Codesupplyco PowerkitAI1/8/202612/8/2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.36%—Codesupplyco PowerkitAI1/8/202612/8/2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.1)0.38%—Codesmiths User Profile BuilderAI1/8/202626/8/2026
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported…
AplazadaMedia (5.4)0.23%—Codeless Page BuilderAI1/8/202626/8/2026
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged…