Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

5631 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.43%—Sourcecodester School Registration AND FEE SystemAI13/9/202614/9/2026
A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI13/9/202619/9/2026
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and…
AplazadaMedia (5.5)0.43%—Sourcecodester School Registration AND FEE SystemAI13/9/202615/9/2026
A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaMedia (5.5)0.43%—Sourcecodester School Registration AND FEE SystemAI13/9/202619/9/2026
A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaAlta (8.1)0.41%—Ayecode UserswpAI11/9/202611/9/2026
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls…
AplazadaCrítica (9.3)0.81%—OpencodeAI10/9/202611/9/2026
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
AplazadaAlta (8.7)0.52%—IcecoderAI10/9/202610/9/2026
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the…
AplazadaAlta (8.7)0.81%—IcecoderAI10/9/202610/9/2026
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as…
AplazadaAlta (8.7)0.61%—IcecoderAI10/9/202610/9/2026
ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI8/9/202610/9/2026
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
AplazadaAlta (7.7)0.47%—Roocode Roo-codeAI8/9/202611/9/2026
Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can craft a command string with an allowlisted word immediately followed…
AnalizadaAlta (7.4)0.92%—Microsoft Visual Studio Code8/9/202610/9/2026
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.87%—Microsoft Visual Studio Code8/9/202615/9/2026
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.2)0.54%—Microsoft Visual Studio Code8/9/202611/9/2026
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.2)0.54%—Microsoft Visual Studio Code8/9/202611/9/2026
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaMedia (6.5)0.76%—Microsoft Visual Studio Code8/9/202611/9/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
AnalizadaCrítica (9.6)0.82%—Microsoft Visual Studio Code8/9/202611/9/2026
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.2)0.51%—Microsoft Visual Studio Code8/9/202611/9/2026
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.2)0.54%—Microsoft Visual Studio Code8/9/202611/9/2026
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.8)0.76%—Microsoft Visual Studio Code8/9/202611/9/2026
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.4)1.0%—Microsoft Visual Studio Code8/9/202611/9/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.8)0.47%—Microsoft Visual Studio Code8/9/202611/9/2026
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
AplazadaAlta (7.7)0.52%—Roocode ROO CodeAI8/9/202619/9/2026
Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted…
AplazadaCrítica (9.8)0.47%—Mfish-nocode-proAI8/9/20269/9/2026
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
AnalizadaMedia (5.9)0.62%—Microsoft Visual Studio Code8/9/202623/9/2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.