Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
5663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Casap Automated Enrollment SystemAI | 29/7/2026 | 1/10/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. | |
| Aplazada | Media (6.1) | 0.19% | — | Sourcecodester Fantastic Blog CMSAI | 29/7/2026 | 5/10/2026 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field. | |
| Aplazada | Alta (7.1) | 0.28% | — | Codesys Profinet ControllerAICodesys ControlAI | 29/7/2026 | 30/7/2026 | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in… | |
| Aplazada | Alta (7.4) | 0.41% | — | Ayecode UserswpAI | 29/7/2026 | 30/7/2026 | The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user. | |
| Analizada | Alta (7.5) | 0.49% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema extensions to reach… | |
| Aplazada | Baja (3.7) | 0.34% | — | Koxudaxi Datamodel-code-generatorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowing credentials scoped to one schema host… | |
| Analizada | Alta (7.5) | 0.30% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in src/datamodel_code_generator/http.py through get_body,… | |
| Aplazada | Alta (7.5) | 0.53% | — | Datamodel Code GeneratorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path,… | |
| Analizada | Alta (7.5) | 0.55% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through… | |
| Aplazada | Alta (8.2) | 0.38% | — | Koxudaxi Datamodel-code-generatorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loopback, private, link-local, metadata,… | |
| Analizada | Alta (8.2) | 0.39% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.9.1 until 0.61.0, datamodel-code-generator silently dereferences attacker-controlled JSON Schema $ref HTTP or HTTPS URLs in… | |
| Analizada | Alta (7.8) | 0.25% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.52.1 until 0.60.2, datamodel-code-generator interpolates validators from --extra-template-data in… | |
| Aplazada | Alta (7.8) | 0.21% | — | Koxudaxi Datamodel-code-generatorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_generator/parser/jsonschema.py in _get_python_type_override are inserted into generated field annotations without sufficient validation, allowing… | |
| Aplazada | Alta (7.8) | 0.21% | — | Datamodel Code GeneratorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2, src/datamodel_code_generator/model/template/TypedDict.jinja2,… | |
| Analizada | Alta (8.8) | 0.71% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in… | |
| Aplazada | Alta (7.8) | 0.21% | — | Datamodel Code GeneratorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja2 are rendered into Python comments… | |
| Aplazada | Crítica (9.1) | 1.2% | — | EasyappointmentsAICodeigniterAI | 27/7/2026 | 30/7/2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema… | |
| Aplazada | Media (4.3) | 0.14% | — | HT Script Insert Headers AND Footers CodeAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Moonshot AI Kimi-codeAI | 27/7/2026 | 27/7/2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for example via prompt injection) can supply a… | |
| Aplazada | Crítica (9.1) | 0.45% | — | Wechat Qrcode LoginAI | 27/7/2026 | 27/7/2026 | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem… | |
| Aplazada | Alta (7.5) | 0.74% | — | Datamodel Code GeneratorAI | 26/7/2026 | 12/8/2026 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Online ClassroomAI | 23/7/2026 | 24/7/2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.3) | 0.31% | — | Code-atlantic Content ControlAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Codex-themes ThegemAI | 23/7/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1. | |
| Aplazada | Media (6.4) | 0.32% | — | Mythemeshop WP ShortcodeAI | 23/7/2026 | 23/7/2026 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode… |