Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.35% | — | Itsourcecode Hospital Management SystemAI | 28/6/2026 | 29/6/2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument loginid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 28/6/2026 | 29/6/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipulation of the argument course_year_section results in sql injection. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 28/6/2026 | 29/6/2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the argument sy leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 28/6/2026 | 29/6/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 28/6/2026 | 29/6/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Pendiente de análisis | Alta (8.8) | 0.50% | — | Ffmpeg LibavcodecAI | 28/6/2026 | 1/9/2026 | FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream… | |
| Aplazada | Media (6.4) | 0.33% | — | Surbma Infusionsoft ShortcodeAI | 27/6/2026 | 29/6/2026 | The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and 'id' shortcode attributes in the… | |
| Aplazada | Media (6.4) | 0.36% | — | Codepeople Post MAPAI | 27/6/2026 | 29/6/2026 | The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.4) | 0.23% | — | Utm.codesAI | 26/6/2026 | 26/6/2026 | Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Designsandcode Forget About Shortcode ButtonsAI | 26/6/2026 | 5/10/2026 | Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions. | |
| Aplazada | Alta (7.5) | 0.61% | — | Webp DecoderAI | 25/6/2026 | 26/6/2026 | The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. | |
| Aplazada | Media (5.4) | 0.29% | — | UPI QR Code Payment GatewayAI | 25/6/2026 | 25/6/2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. | |
| Aplazada | Alta (8.8) | 0.51% | — | Email Address Encoder Email Encoder PremiumAITillkruss Email Address EncoderAI | 25/6/2026 | 25/6/2026 | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks | |
| Analizada | Media (6.9) | 0.76% | — | Kidocode Crawl4ai | 24/6/2026 | 26/6/2026 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service… | |
| Aplazada | Media (6.4) | 0.32% | — | MIR Blocks AND ShortcodesAI | 24/6/2026 | 30/6/2026 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of the 'msc_stats' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on… | |
| Analizada | Alta (7.5) | 1.6% | 💥 Exploit | Kidocode Crawl4ai | 23/6/2026 | 29/6/2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through it, reaching internal… | |
| Analizada | Alta (7.5) | 0.43% | — | Kidocode Crawl4ai | 23/6/2026 | 29/6/2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker could reach internal services… | |
| Analizada | Crítica (10) | 2.9% | 💥 Exploit | Kidocode Crawl4ai | 23/6/2026 | 29/6/2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with… | |
| Analizada | Media (6) | 0.52% | 💥 PoC | Anthropic Claude Code | 23/6/2026 | 29/6/2026 | Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools… | |
| Analizada | Media (5.3) | 0.34% | — | Kidocode Crawl4ai | 23/6/2026 | 25/6/2026 | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl request with malicious markup that executes in an operator's browser when viewing the dashboard. | |
| Analizada | Crítica (9.2) | 0.91% | — | Kidocode Crawl4ai | 23/6/2026 | 25/6/2026 | Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. Remote attackers can exploit insufficient… | |
| Analizada | Crítica (9.2) | 0.48% | — | Kidocode Crawl4ai | 22/6/2026 | 30/6/2026 | Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services… | |
| Analizada | Alta (7.5) | 0.48% | — | Encode Starlette | 22/6/2026 | 26/6/2026 | Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated… | |
| Analizada | Media (5.3) | 0.27% | — | Encode Starlette | 22/6/2026 | 26/6/2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves… | |
| Analizada | Crítica (9.3) | 2.6% | 💥 Exploit | Kidocode Crawl4ai | 21/6/2026 | 26/6/2026 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality. |