Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

5675 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.
AplazadaMedia (6.4)0.32%—Email Encoder Protect Email Addresses AND Phone NumbersAI16/4/202617/6/2026
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.4)0.24%—Codesolz Better Find AND ReplaceAI16/4/202617/6/2026
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaMedia (6.1)0.29%—CodecolorerAI16/4/202617/6/2026
The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.4)0.32%—Shortcodes UltimateAI16/4/202614/8/2026
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaCrítica (9.8)0.78%—Barcode ScannerAI16/4/202617/6/2026
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID…
AplazadaAlta (8)0.33%—Codeium WindsurfAI15/4/202617/6/2026
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registration of a malicious…
AplazadaAlta (8.4)0.56%—Codethat ShoppingcartAI15/4/202617/6/2026
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field
AplazadaMedia (6.4)0.33%—Coachific ShortcodeAI15/4/202617/6/2026
The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() on the 'userhash' parameter, which strips…
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment SchedulerAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
AplazadaBaja (2.7)0.39%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
AplazadaBaja (2.7)0.32%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.
Pendiente de análisisCrítica (9.8)6.6%—Openai Codex CLIAI14/4/20265/7/2026
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and…
AplazadaMedia (6.4)0.15%—Surbma Booking COM ShortcodeAI14/4/202617/6/2026
The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaBaja (2.1)0.32%—Code-projects Easy Blog SiteAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.