Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Ingredients Stock Management SystemAI | 1/6/2026 | 22/7/2026 | A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been published and may… | |
| Aplazada | Baja (2.1) | 0.20% | — | Code-projects Online Hospital Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.26% | — | Code-projects Online Hospital Management SystemAI | 1/6/2026 | 22/7/2026 | A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Alta (8.1) | 0.48% | — | Perl Sereal DecoderAI | 31/5/2026 | 22/7/2026 | Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Online Hospital Management SystemAI | 31/5/2026 | 22/7/2026 | A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 31/5/2026 | 22/7/2026 | A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 31/5/2026 | 22/7/2026 | A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Online Music SiteAI | 31/5/2026 | 22/7/2026 | A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Aplazada | Baja (2) | 0.21% | — | Code-projects Online Music SiteAI | 31/5/2026 | 22/7/2026 | A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (2.1) | 0.24% | 💥 PoC | Code-projects Visitor Management SystemAI | 31/5/2026 | 22/7/2026 | A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.31% | 💥 PoC | Code-projects Student Details Management SystemAI | 30/5/2026 | 22/7/2026 | A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.1) | 0.26% | — | Sourcecodester Doctor Appointment SystemAI | 29/5/2026 | 21/7/2026 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php. | |
| Aplazada | Alta (7.8) | 0.21% | — | Roslyn Codelens MCP ServerAI | 29/5/2026 | 21/7/2026 | Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without any allowlist, signature check, or user confirmation;… | |
| Aplazada | Media (6.4) | 0.33% | — | Simple Divi ShortcodeAI | 29/5/2026 | 21/7/2026 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id'… | |
| Analizada | Alta (8.7) | 0.42% | — | Hkuds Deepcode | 28/5/2026 | 14/7/2026 | DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path… | |
| Aplazada | Crítica (9.6) | 0.47% | — | CodewhaleAI | 28/5/2026 | 17/6/2026 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_approve defaults to true (task_manager.rs:297: auto_approve: Some(true)).… | |
| Aplazada | Alta (7.4) | 0.42% | — | CodewhaleAI | 28/5/2026 | 17/6/2026 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as http://[::1], the SSRF defenses do not work. This vulnerability is fixed in 0.8.26. | |
| Aplazada | Crítica (9.6) | 0.69% | — | CodewhaleAI | 28/5/2026 | 17/6/2026 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and executes arbitrary code: test binaries, build.rs build scripts, and proc… | |
| Aplazada | Alta (7.4) | 0.37% | — | Deepseek CodewhaleAI | 28/5/2026 | 17/6/2026 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the… | |
| Analizada | Alta (7.1) | 0.50% | — | Networktocode Nautobot | 28/5/2026 | 17/6/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not intended to be user-editable. Doing so could cause Nautobot's local… | |
| Analizada | Alta (8.5) | 0.40% | — | Networktocode Nautobot | 28/5/2026 | 17/6/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various… | |
| Analizada | Media (6.5) | 0.56% | — | Networktocode Nautobot | 28/5/2026 | 17/6/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the find field in combination with the… | |
| Analizada | Media (5.4) | 0.30% | — | Networktocode Nautobot | 28/5/2026 | 17/6/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or… | |
| Analizada | Alta (8.6) | 0.21% | — | Cnighswonger Claude-code-cache-fix | 27/5/2026 | 17/6/2026 | claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-controlled field of the payload closes the… | |
| Aplazada | Media (5.4) | 0.23% | — | Creatorsofcode SimplephpAI | 27/5/2026 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload. |