Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.45% | — | Sourcecodester Indian Invoicing SystemAI | 25/5/2026 | 20/7/2026 | A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. The manipulation of the argument msg leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.35% | — | Sourcecodester Indian Invoicing SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Multiple… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Indian Invoicing SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation Handler. Performing a manipulation of the argument customer_name/category results in sql injection. The attack can be initiated… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Electronic Judging SystemAI | 24/5/2026 | 23/7/2026 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester SUP Online ShoppingAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 24/5/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage_history.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 24/5/2026 | 23/7/2026 | A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_patient_history. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 23/5/2026 | 23/7/2026 | A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the… | |
| Analizada | Media (6.9) | 0.24% | — | Codesys Visualization | 21/5/2026 | 23/7/2026 | The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session. | |
| Aplazada | Media (6.1) | 0.27% | — | Email EncoderAI | 20/5/2026 | 24/7/2026 | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks | |
| Analizada | Baja (2.1) | 0.48% | — | Kilo Code CLI | 17/5/2026 | 17/6/2026 | A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the… | |
| Analizada | Baja (2.1) | 0.78% | — | Kilo Code | 17/5/2026 | 17/6/2026 | A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is possible to… | |
| Aplazada | Crítica (10) | 0.16% | — | Enchantedcode Note MarkAI | 14/5/2026 | 17/6/2026 | Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4. | |
| Aplazada | Alta (8.6) | 0.72% | — | Enchantedcode Note MarkAI | 14/5/2026 | 17/6/2026 | Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, where the asset filename is provided through the X-Name HTTP request header. This value is stored directly in the… | |
| Modificada | Media (5.9) | 0.58% | — | Bytecodealliance Wasmtime | 14/5/2026 | 28/7/2026 | Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible… | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Baja (3.3) | 0.50% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5) | 0.71% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 12/5/2026 | 10/8/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Media Encoder | 12/5/2026 | 28/8/2026 | Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Media Encoder | 12/5/2026 | 28/8/2026 | Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Pendiente de análisis | Alta (8.7) | 0.44% | 💥 PoC | Code Runner MCP ServerAI | 12/5/2026 | 17/6/2026 | A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unauthenticated remote attacker can invoke the run-code MCP tool to supply arbitrary source code and execute it via… | |
| Aplazada | Media (6.4) | 0.32% | — | Bootstrap ShortcodeAI | 12/5/2026 | 17/6/2026 | The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.35% | — | ShortcodelyAI | 12/5/2026 | 17/6/2026 | The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.32% | — | Credits ShortcodeAI | 12/5/2026 | 17/6/2026 | The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |