Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2714▼ 164 respecto a la semana anterior
Críticas / altas1235▼ 317 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
5675 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Employee Management SystemAI | 26/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2) | 0.33% | 💥 PoC | Codeastro Online JOB PortalAI | 26/4/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely.… | |
| Analizada | Crítica (9.3) | 0.61% | — | Ericsson Codechecker | 24/4/2026 | 17/6/2026 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue… | |
| Aplazada | Media (5.3) | 0.43% | — | Codepeople Booking Calendar Contact FormAI | 24/4/2026 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Alta (8.7) | 0.57% | — | Codesys Ethernet IP AdapterAI | 23/4/2026 | 17/6/2026 | An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections. | |
| Aplazada | Media (6.5) | 0.13% | — | Rescuethemes Rescue ShortcodesAI | 23/4/2026 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Rescue Themes Rescue Shortcodes permite XSS Almacenado. Este problema afecta a Rescue Shortcodes: desde n/a hasta 3.3. | |
| Aplazada | Media (6.4) | 0.32% | — | Simple Random Posts ShortcodeAI | 22/4/2026 | 17/6/2026 | The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the 'simple_random_posts' shortcode in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Analizada | Alta (7.7) | 0.80% | — | Anthropic Claude Code | 21/4/2026 | 17/6/2026 | Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symlink and wrote to… | |
| Aplazada | Baja (3.5) | 0.21% | — | Email EncoderAI | 20/4/2026 | 17/6/2026 | The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.15% | 💥 PoC | Anthropic Claude Code | 17/4/2026 | 17/6/2026 | Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData directory is writable by non-administrative… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Codeastro Simple Attendance Management SystemAI | 17/4/2026 | 17/6/2026 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php. | |
| Aplazada | Baja (3.7) | 0.31% | — | Enchantedcode Note MarkAI | 17/4/2026 | 17/6/2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only when the supplied username exists, returning immediately for nonexistent usernames. This timing discrepancy allows unauthenticated attackers to enumerate valid usernames by… | |
| Aplazada | Alta (8.7) | 0.42% | — | Enchantedcode Note MarkAI | 17/4/2026 | 17/6/2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte detection for content type, which does not identify text-based formats such as HTML, SVG, or XHTML. These files are served with an empty Content-Type, no… | |
| Pendiente de análisis | Alta (8.3) | 0.48% | — | Snowflake Cortex Code CLIAI | 16/4/2026 | 17/6/2026 | Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository, causing the CLI agent to execute arbitrary… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | |
| Aplazada | Media (4.7) | 0.27% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php. |