Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.28% | — | Sourcecodester Pizzafy E-commerce SystemAI | 3/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.30% | — | Sourcecodester Online Food Ordering SystemAI | 3/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.21% | — | Sourcecodester Online Boat Reservation SystemAI | 3/6/2026 | 22/7/2026 | A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.31% | — | Johnhuang316 Code-index-mcpAI | 3/6/2026 | 22/7/2026 | A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.24% | — | Sourcecodester Human Resource ManagementAI | 2/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument employeeid leads to improper control of resource identifiers. The attack may be… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Student Admission SystemAI | 2/6/2026 | 22/7/2026 | A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.3) | 0.60% | — | Zauberzeug NiceguiAITiangolo FastapiAIEncode StarletteAIEncode UvicornAI | 2/6/2026 | 22/7/2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse,… | |
| Aplazada | Alta (8.1) | 0.56% | — | PHPAICodesupplyco BlueprintAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. | |
| Aplazada | Media (6.4) | 0.32% | — | Demomentsomtres ShortcodesAI | 2/6/2026 | 22/7/2026 | The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortcode attributes within the st_callout()… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 2/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 2/6/2026 | 22/7/2026 | A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.27% | — | Itsourcecode Fees Management SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2) | 0.27% | — | Code-projects Online Hospital Management SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.25% | — | Itsourcecode Fees Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (1.9) | 0.12% | — | Sourcecodester Customer Review APPAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service. The attack requires a local approach. The exploit… | |
| Aplazada | Media (5.5) | 0.32% | 💥 PoC | Code-projects Hotel AND Tourism Reservation SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (7.2) | 0.17% | — | CodexbarAI | 1/6/2026 | 22/7/2026 | CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the same host can read the App Store Connect… | |
| Aplazada | Alta (7.5) | 0.48% | — | CodexbarAI | 1/6/2026 | 22/7/2026 | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a privileged shell payload into it, and… | |
| Aplazada | Baja (2.1) | 0.34% | 💥 PoC | Code-projects Hotel AND Tourism Reservation SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.50% | 💥 PoC | Code-projects Hotel AND Tourism Reservation SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely.… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester SEO Meta TAG ExtractorAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Payroll SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. |