Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 1.0% | 💥 PoC | Ffmpeg LibavcodecAI | 18/6/2026 | 23/7/2026 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2. | |
| Aplazada | Baja (2.7) | 0.27% | — | Ayecode UserswpAI | 18/6/2026 | 18/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it… | |
| Analizada | Media (5.3) | 0.35% | — | Encode Starlette | 17/6/2026 | 26/6/2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is… | |
| Aplazada | Media (6.9) | 0.28% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 17/6/2026 | 18/6/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack… | |
| Modificada | Alta (7.5) | 0.65% | — | Encode Starlette | 17/6/2026 | 4/8/2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for… | |
| Aplazada | Alta (8.2) | 0.37% | — | Codection Clean LoginAI | 17/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Fs-code BookneticAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Implecode Ecommerce Product CatalogAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. | |
| Analizada | Alta (7.5) | 0.50% | — | Bytecodealliance Wasmtime | 15/6/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the wasip2 descriptor.open-at or wasip1 path_open interfaces by opening a file with… | |
| Aplazada | Alta (7.1) | 0.25% | 💥 PoC | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Ayecode GetpaidAI | 15/6/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49. | |
| Aplazada | Media (5.4) | 0.27% | — | Codepeople Form Builder CPAI | 15/6/2026 | 21/7/2026 | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page… | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 14/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2) | 0.21% | — | Codeastro Student Attendance Management SystemAI | 13/6/2026 | 23/7/2026 | A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.25% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is… | |
| Aplazada | Baja (2) | 0.20% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack may be launched remotely. The exploit… | |
| Aplazada | Baja (2) | 0.20% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Media (6) | 0.42% | — | CodexbarAI | 11/6/2026 | 14/7/2026 | CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies,… | |
| Analizada | Media (5.5) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 9/6/2026 | 24/8/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.6) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (8.4) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |