Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Coderastro Simple Online Leave Management SystemAI | 13/7/2026 | 14/7/2026 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Analizada | Alta (8.8) | 0.65% | — | Kidocode Crawl4ai | 12/7/2026 | 14/7/2026 | Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the… | |
| Analizada | Alta (8.8) | 0.43% | — | Kidocode Crawl4ai | 12/7/2026 | 14/7/2026 | Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious… | |
| Aplazada | Alta (8.4) | 0.35% | — | ChromiumAIPraisonaiAIKidocode Crawl4aiAI | 11/7/2026 | 13/7/2026 | PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling… | |
| Aplazada | Alta (8.8) | 0.85% | — | Code EngineAI | 11/7/2026 | 29/9/2026 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 1.1% | — | Smackcoders WP Ultimate CSV ImporterAI | 11/7/2026 | 13/7/2026 | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and… | |
| Analizada | Crítica (9.2) | 0.51% | — | Kidocode Crawl4ai | 10/7/2026 | 13/7/2026 | Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata… | |
| Aplazada | Media (4.3) | 0.39% | — | Codection Import AND Export Users AND CustomersAI | 10/7/2026 | 10/7/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw… | |
| Aplazada | Media (4.4) | 0.34% | — | Highlighting Code BlockAI | 10/7/2026 | 10/7/2026 | The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Alta (8.3) | 0.52% | — | Quram Libimagecodec.mediaAI | 10/7/2026 | 10/7/2026 | Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. | |
| Aplazada | Alta (8.3) | 0.52% | 💥 PoC | Qualcomm Libimagecodec.media.quramAI | 10/7/2026 | 10/7/2026 | Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. | |
| Aplazada | Media (6.4) | 0.33% | — | Sudoku ShortcodeAI | 10/7/2026 | 10/7/2026 | The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in the 'sudoku-sc' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Media (4.4) | 0.33% | — | Github CLIAIGithub CodespaceAIMicrosoft Visual Studio CodeAI | 9/7/2026 | 14/7/2026 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS… | |
| Aplazada | Alta (8.8) | 0.69% | — | Ayecode UserswpAI | 9/7/2026 | 10/7/2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 9/7/2026 | 9/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Alta (7.2) | 1.2% | — | Code-atlantic Popup MakerAI | 9/7/2026 | 9/7/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Interview Management SystemAI | 9/7/2026 | 9/7/2026 | A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Food Order SystemAI | 9/7/2026 | 9/7/2026 | A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Simple Online Leave Management SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (6.5) | 0.17% | — | Bytecodealliance WasmtimeAI | 8/7/2026 | 10/7/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as… | |
| Aplazada | Alta (8.7) | 0.43% | — | Udecode PlateAI | 8/7/2026 | 10/7/2026 | Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata in useMediaState and skips parseMediaUrl protocol validation, allowing a crafted Plate document to set a known video provider while keeping url as a javascript: iframe… | |
| Aplazada | Media (6.8) | 0.28% | — | Code 27 Companion HUBAI | 8/7/2026 | 9/7/2026 | A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset | |
| Aplazada | Media (6.8) | 0.28% | 💥 PoC | Code27 Companion HUBAIGoogle Android Debug BridgeAI | 8/7/2026 | 10/7/2026 | An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components | |
| Analizada | Media (6.8) | 0.22% | — | Coder | 8/7/2026 | 8/7/2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was… | |
| Analizada | Media (5.4) | 0.32% | — | Coder | 8/7/2026 | 8/7/2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace… |