Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.47%—Xpoda Turkiye Informatics Technology INC NO Code PlatformAI22/7/202630/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4.
Pendiente de análisisAlta (7.8)0.82%—Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI22/7/202622/7/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be…
Pendiente de análisisAlta (7.8)0.75%—Ansible LightspeedAIMicrosoft Visual Studio CodeAI22/7/202623/7/2026
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation…
Pendiente de análisisAlta (7.8)0.95%—Microsoft Visual Studio CodeAIRedhat AnsibleAI22/7/202622/7/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to…
Pendiente de análisisBaja (3.3)0.13%—Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI22/7/202622/7/2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI22/7/202622/7/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for…
AplazadaBaja (1.3)1.5%—Qusetions Minicode-pythonAI22/7/202622/7/2026
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI21/7/202622/7/2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI21/7/202622/7/2026
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI21/7/202622/7/2026
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI21/7/202622/7/2026
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
AplazadaAlta (8.2)0.36%—Agenticmail ClaudecodeAIAgenticmail CoreAICodexnotes CodexAIOpenclawAI20/7/202623/7/2026
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without…
AplazadaMedia (6.3)0.17%—Ai-sdk Harness OpencodeAIHarness AgentAIOpencodeAI20/7/202623/7/2026
The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (`host-tool-mcp.mjs`). This allows untrusted code executing in the sandbox to invoke…
AplazadaMedia (6.3)0.17%—Ai-sdk Harness-opencodeAIOpenai Codex-sdkAI20/7/202623/7/2026
The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to version 1.0.29, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (the Codex CLI shim). This allows untrusted code…
AplazadaAlta (8.7)0.29%—Lanol FilecodeboxAI20/7/202623/7/2026
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique…
AplazadaAlta (7.7)1.8%—Roocode ROO CodeAI20/7/202623/7/2026
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque…
AplazadaAlta (8.7)0.37%—CodeigniterAICi4-cms-erp Ci4msAI20/7/202621/7/2026
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` →…
AplazadaMedia (6.5)0.48%—CodeigniterAICi4-cms-erp Ci4msAI20/7/202621/7/2026
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive endpoints — `deleteFileOrFolder` and…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI20/7/202620/7/2026
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been…
AplazadaMedia (5.4)0.24%—Codeigniter 4AICi4-cms-erp Ci4msAI20/7/202621/7/2026
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently…
AplazadaBaja (2.1)0.47%—Itsourcecode Courier Management SystemAI19/7/202621/7/2026
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202620/7/2026
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202622/7/2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be…
AplazadaMedia (5.1)0.38%—Sourcecodester Pizzafy Ecommerce SystemAI19/7/202620/7/2026
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.
AplazadaBaja (2.1)0.47%—Code-projects Online Examination SystemAI19/7/202622/7/2026
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be…