Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

5667 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Surbma Yoast SEO Breadcrumb ShortcodeAI2/7/20262/7/2026
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
AplazadaAlta (7.1)0.25%—Implecode Ecommerce Product CatalogAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
AnalizadaBaja (2.3)0.37%—Bytecodealliance Wasmtime1/7/20262/7/2026
Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those before 44.0.3; and versions 45.0.0 and 45.0.1 contain a native implementation of WASIp1 which suffers from a leak in the fd_renumber function where the file descriptor being…
AplazadaMedia (4.3)0.33%—Codexpert INC ThumbpressAI1/7/20261/7/2026
Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.
AplazadaMedia (6.5)0.22%—Averta Shortcodes AND Extra Features FOR Phlox ThemeAI1/7/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows DOM-Based XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.22.
AnalizadaCrítica (9.2)0.49%—Kidocode Crawl4ai30/6/20266/7/2026
Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can execute arbitrary JavaScript and, combined…
AplazadaAlta (7.1)0.40%—Iocoder Yudao-cloudAI30/6/202614/7/2026
yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the @PreAuthorize annotation. Attackers can query…
ModificadaMedia (5.5)0.14%—IBM Devops DeployIBM Urbancode Deploy30/6/202630/7/2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy stores potentially sensitive information in log files that could be read by a local user.
AnalizadaMedia (6.5)0.38%—IBM Devops DeployIBM Urbancode Deploy30/6/20262/7/2026
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
AplazadaMedia (6.6)0.51%—Decode-uri-componentAI30/6/202630/6/2026
decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker…
AnalizadaAlta (7.7)0.69%—Anthropic Claude Code29/6/202630/6/2026
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree…
AnalizadaMedia (4.4)0.15%—Anthropic Claude Code29/6/202630/6/2026
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755),…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be launched remotely. The exploit has been made…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing a manipulation of the argument editid results in sql injection. The attack may be initiated remotely. The exploit has been released…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202630/6/2026
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of the argument patientid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaMedia (5.5)0.51%—Sourcecodester Simple Food Ordering SystemAI29/6/202629/6/2026
A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used.
AplazadaBaja (2)0.33%—Sourcecodester Inventory Management SystemAI29/6/202629/6/2026
A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting. The attack is possible to be carried out…
AplazadaMedia (5.5)0.47%—Sourcecodester Inventory Management SystemAI29/6/20261/7/2026
A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls. Remote exploitation of the attack is…
AplazadaBaja (2.1)0.47%—Code-projects Online Music SiteAI29/6/202629/6/2026
A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The attack may be launched remotely. The…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI29/6/202630/6/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /preview3.php. The manipulation of the argument course_year_section leads to sql injection. The attack may be initiated remotely. The exploit is publicly available…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI29/6/202629/6/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_class1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.43%—Code-projects Real State ServicesAI29/6/202629/6/2026
A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could…
AplazadaBaja (2)0.35%—Codeagstro Complaint Management SystemAI29/6/202629/6/2026
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is…
AplazadaBaja (2.1)0.47%—Itsourcecode Online Hotel Management SystemAI29/6/202629/6/2026
A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched…
AplazadaBaja (2.1)0.47%—Itsourcecode Online Hotel Management SystemAI29/6/20261/7/2026
A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The…