Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 300 respecto a la semana anterior
Críticas / altas1352▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5631 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.22% | — | Code16 SharpAI | 24/9/2026 | 29/9/2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve… | |
| Aplazada | Alta (7.3) | 0.21% | — | Code16 SharpAI | 24/9/2026 | 30/9/2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is… | |
| Aplazada | Alta (8.8) | 0.33% | — | Codection Import AND Export Users AND CustomersAI | 23/9/2026 | 24/9/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape… | |
| Aplazada | Media (4.8) | 0.19% | — | Captcha CodeAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Smart Attendance System With QR Code ScannerAI | 23/9/2026 | 23/9/2026 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 23/9/2026 | 23/9/2026 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 23/9/2026 | 23/9/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 22/9/2026 | 23/9/2026 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 22/9/2026 | 25/9/2026 | A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Leave Management SystemAI | 22/9/2026 | 23/9/2026 | A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Crítica (9.1) | 0.34% | — | OpencodeAI | 22/9/2026 | 24/9/2026 | Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload. | |
| Aplazada | Baja (2.1) | 1.7% | — | Moonshot AI Kimi CodeAI | 22/9/2026 | 22/9/2026 | A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts of the component MCP Configuration Loader. The manipulation results in os command injection. The attack may be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… | |
| Aplazada | Alta (7.5) | 0.68% | — | NET IDN PunycodeAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed bytes, as the :utf8 PerlIO layer produces from any malformed input,… | |
| Aplazada | Crítica (9.1) | 0.63% | — | NET IDN Punycode PPAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string… | |
| Aplazada | Alta (7.5) | 0.63% | — | NET IDN PunycodeAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan… | |
| Aplazada | Crítica (9.1) | 0.65% | — | Perl NET IDN PunycodeAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the… | |
| Aplazada | Alta (8.4) | 0.19% | — | NET IDN PunycodeAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first… | |
| Aplazada | Media (6.5) | 0.52% | — | NET IDN PunycodeAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed int. The accumulation `delta += (m-n) * (h+1)` has no overflow check, so a large… | |
| Aplazada | Crítica (9.8) | 0.42% | — | NET IDN PunycodeAI | 22/9/2026 | 22/9/2026 | Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for… | |
| Aplazada | Baja (2) | 0.40% | — | Codeastro QR Code Attendance Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Drug Recommendation SystemAI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Drug Recommendation SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Drug Recommendation SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch… |