Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5631 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | Ayecode Location ManagerAI | 18/9/2026 | 18/9/2026 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (5.3) | 0.37% | — | Codection Clean LoginAI | 18/9/2026 | 18/9/2026 | The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it. | |
| Aplazada | Media (5.3) | 0.30% | — | Codection Clean LoginAI | 18/9/2026 | 18/9/2026 | The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Matrimonial SystemAI | 17/9/2026 | 17/9/2026 | A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.5) | 0.53% | — | Sourcecodester Drug Recommendation SystemAI | 17/9/2026 | 21/9/2026 | A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Leave Management SystemAI | 16/9/2026 | 22/9/2026 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Inventory AND Monitoring SystemAI | 16/9/2026 | 16/9/2026 | A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Inventory AND Monitoring SystemAI | 16/9/2026 | 16/9/2026 | A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may… | |
| En análisis | Media (6.5) | 0.55% | — | VllmAINvidia PynvvideocodecAI | 16/9/2026 | 30/9/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMediaIO even when startup configuration selected a software… | |
| Aplazada | Media (5.5) | 0.56% | — | Code-projects Matrimonial SystemAI | 16/9/2026 | 16/9/2026 | A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated… | |
| Aplazada | Media (6.1) | 0.34% | — | Udecode PlateAI | 16/9/2026 | 16/9/2026 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML… | |
| Aplazada | Baja (1.9) | 0.38% | — | Sourcecodester Online Food Ordering SystemAI | 16/9/2026 | 22/9/2026 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Leave Management SystemAI | 16/9/2026 | 16/9/2026 | A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Pendiente de análisis | Media (5.1) | 0.26% | — | Kidocode Crawl4aiAI | 15/9/2026 | 17/9/2026 | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to… | |
| Pendiente de análisis | Alta (8.3) | 0.35% | — | Kidocode Crawl4aiAI | 15/9/2026 | 16/9/2026 | Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal… | |
| Pendiente de análisis | Media (5.1) | 0.24% | — | Kidocode Crawl4aiAI | 15/9/2026 | 17/9/2026 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for… | |
| Pendiente de análisis | Alta (8.7) | 0.46% | — | Kidocode Crawl4aiAI | 15/9/2026 | 16/9/2026 | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any… | |
| Aplazada | Alta (8.7) | 0.51% | — | Netty-incubator-codec-ohttpAI | 15/9/2026 | 30/9/2026 | netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequestResponseContext.java allocates a pooled direct ByteBuf for decrypted plaintext… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Record Management SystemAI | 15/9/2026 | 22/9/2026 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Pendiente de análisis | Alta (8.3) | 0.76% | — | CoderAI | 15/9/2026 | 30/9/2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Kidocode Crawl4aiAI | 15/9/2026 | 19/9/2026 | Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and… | |
| Aplazada | Alta (8.6) | 0.21% | — | CoderagAI | 15/9/2026 | 30/9/2026 | CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke… | |
| Pendiente de análisis | Media (6.5) | 0.59% | — | Pipelines-as-codeAITektonAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple… | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | Cd.foundation Pipelines AS CodeAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature… | |
| Aplazada | Alta (7) | 0.14% | — | Wso2 Integrator MI VS Code ExtensionAI | 15/9/2026 | 18/9/2026 | The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow. Successful… |