Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5631 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 13/9/2026 | 19/9/2026 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 15/9/2026 | A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester School Registration AND FEE SystemAI | 13/9/2026 | 19/9/2026 | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Alta (8.1) | 0.41% | — | Ayecode UserswpAI | 11/9/2026 | 11/9/2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls… | |
| Aplazada | Crítica (9.3) | 0.81% | — | OpencodeAI | 10/9/2026 | 11/9/2026 | knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system. | |
| Aplazada | Alta (8.7) | 0.52% | — | IcecoderAI | 10/9/2026 | 10/9/2026 | ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the… | |
| Aplazada | Alta (8.7) | 0.81% | — | IcecoderAI | 10/9/2026 | 10/9/2026 | ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as… | |
| Aplazada | Alta (8.7) | 0.61% | — | IcecoderAI | 10/9/2026 | 10/9/2026 | ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 8/9/2026 | 10/9/2026 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.7) | 0.47% | — | Roocode Roo-codeAI | 8/9/2026 | 11/9/2026 | Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can craft a command string with an allowlisted word immediately followed… | |
| Analizada | Alta (7.4) | 0.92% | — | Microsoft Visual Studio Code | 8/9/2026 | 10/9/2026 | Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.87% | — | Microsoft Visual Studio Code | 8/9/2026 | 15/9/2026 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Media (6.5) | 0.76% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Crítica (9.6) | 0.82% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.2) | 0.51% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.4) | 1.0% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Aplazada | Alta (7.7) | 0.52% | — | Roocode ROO CodeAI | 8/9/2026 | 19/9/2026 | Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Mfish-nocode-proAI | 8/9/2026 | 9/9/2026 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | |
| Analizada | Media (5.9) | 0.62% | — | Microsoft Visual Studio Code | 8/9/2026 | 23/9/2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. |