Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
5675 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php. | |
| Aplazada | Media (6.4) | 0.32% | — | Email Encoder Protect Email Addresses AND Phone NumbersAI | 16/4/2026 | 17/6/2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.24% | — | Codesolz Better Find AND ReplaceAI | 16/4/2026 | 17/6/2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Media (6.1) | 0.29% | — | CodecolorerAI | 16/4/2026 | 17/6/2026 | The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.4) | 0.32% | — | Shortcodes UltimateAI | 16/4/2026 | 14/8/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Barcode ScannerAI | 16/4/2026 | 17/6/2026 | The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID… | |
| Aplazada | Alta (8) | 0.33% | — | Codeium WindsurfAI | 15/4/2026 | 17/6/2026 | A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registration of a malicious… | |
| Aplazada | Alta (8.4) | 0.56% | — | Codethat ShoppingcartAI | 15/4/2026 | 17/6/2026 | Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field | |
| Aplazada | Media (6.4) | 0.33% | — | Coachific ShortcodeAI | 15/4/2026 | 17/6/2026 | The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() on the 'userhash' parameter, which strips… | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment SchedulerAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php. | |
| Aplazada | Baja (2.7) | 0.39% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php. | |
| Aplazada | Baja (2.7) | 0.32% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php. | |
| Pendiente de análisis | Crítica (9.8) | 6.6% | — | Openai Codex CLIAI | 14/4/2026 | 5/7/2026 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and… | |
| Aplazada | Media (6.4) | 0.15% | — | Surbma Booking COM ShortcodeAI | 14/4/2026 | 17/6/2026 | The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Easy Blog SiteAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |