Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
5675 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Patient Record Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Patient Record Management SystemAI | 10/4/2026 | 17/6/2026 | A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Aplazada | Media (6.4) | 0.20% | — | Addfunc Head Footer CodeAI | 10/4/2026 | 17/6/2026 | The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` post meta values in all versions up to, and including, 2.3. This is due to the plugin outputting these meta values without any sanitization or escaping.… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 10/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument cat_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Simple IT Discussion ForumAI | 10/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Library Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made… | |
| Aplazada | Media (4.3) | 0.40% | — | Ayecode UserswpAI | 10/4/2026 | 17/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation in the upload_file_remove() AJAX handler where the $htmlvar… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.php. The manipulation of the argument user_Id results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used… | |
| Analizada | Media (6.1) | 0.26% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's realloc is not validated before the host attempts to write through the pointer. This enables a guest to… | |
| Analizada | Media (6.1) | 0.37% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For 32-bit tables this means that the result of the operator, internally in Winch, is tagged as… | |
| Analizada | Baja (2.3) | 0.30% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be leaked from one instance to the next. The implementation of resetting the virtual memory… | |
| Analizada | Crítica (9) | 0.49% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox. This vulnerability requires use of the Winch compiler… | |
| Analizada | Baja (1) | 0.12% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of embedder API calls made by the host. Specifically, the following steps must occur to… | |
| Modificada | Crítica (9) | 0.39% | — | Bytecodealliance Wasmtime | 9/4/2026 | 15/7/2026 | Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks a guest WebAssembly… | |
| Analizada | Media (5.9) | 0.42% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means that a valid guest can be compiled with Winch, on any architecture, and cause the host… | |
| Analizada | Baja (2.3) | 0.38% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the table.size instruction. This bug could lead to disclosing data on the host's stack to… | |
| Analizada | Media (4.1) | 0.26% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the f64x2.splat WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When signals-based-traps are disabled this can result in a uncaught… | |
| Analizada | Media (5.6) | 0.39% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic which can happen when a flags-typed component model value is lifted with the Val type. If bits are set outside of the set of flags the component model specifies that these bits should be ignored but… | |
| Analizada | Media (5.9) | 0.42% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 or latin1+utf16 encodings improperly verified the alignment of reallocated strings. This meant that unaligned pointers could be passed to the host for… | |
| Analizada | Media (6.9) | 0.46% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would incorrectly validate the byte length of the input string when performing a bounds check. Specifically the… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects unknown code of the file /topic-details.php. The manipulation of the argument post_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Media (5.5) | 0.20% | — | Osslsigncode Project Osslsigncode | 9/4/2026 | 17/6/2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When processing PE sections for page hashing, the function uses PointerToRawData… | |
| Analizada | Media (5.5) | 0.20% | — | Osslsigncode Project Osslsigncode | 9/4/2026 | 17/6/2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When page hash processing is performed on a PE file, the function subtracts hdrsize… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Patient Record Management SystemAI | 9/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made… | |
| Analizada | Alta (7.8) | 0.23% | — | Osslsigncode Project Osslsigncode | 9/4/2026 | 17/6/2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7 signature, the code copies the digest value from a parsed SpcIndirectDataContent structure… |