Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 28/6/2026 | 29/6/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.3) | 0.44% | — | Rentmy Real Time Rental ManagementAI | 24/6/2026 | 25/6/2026 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create,… | |
| Pendiente de análisis | Media (5.1) | 0.20% | — | Caliptra Core Runtime FirmwareAI | 24/6/2026 | 25/6/2026 | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of… | |
| Pendiente de análisis | Alta (7.2) | 0.24% | — | Caliptra Core Runtime FirmwareAI | 24/6/2026 | 25/6/2026 | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. | |
| Aplazada | Alta (8.7) | 0.63% | — | Wordpress Time CapsuleAI | 20/6/2026 | 29/9/2026 | WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the… | |
| Analizada | Media (5.3) | 0.21% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Media (5.3) | 0.23% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0. | |
| Analizada | Media (4.6) | 0.39% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Analizada | Media (5.1) | 0.23% | — | Microchip Gridtime 3000 Firmware | 19/6/2026 | 9/7/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Aplazada | Alta (8.5) | 0.17% | — | Realtimes Desktop ServiceAI | 19/6/2026 | 29/9/2026 | RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system… | |
| Aplazada | Alta (8.5) | 0.36% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. | |
| Analizada | Alta (7.5) | 0.50% | — | Bytecodealliance Wasmtime | 15/6/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the wasip2 descriptor.open-at or wasip1 path_open interfaces by opening a file with… | |
| Aplazada | Alta (7.1) | 0.25% | 💥 PoC | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions. | |
| Aplazada | Media (4.3) | 0.30% | — | SolidtimeAI | 12/6/2026 | 17/6/2026 | Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members API. The Jetstream web team page authorizes access with only belongsToTeam() and then loads and serializes all pending… | |
| Analizada | Alta (8.2) | 0.06% | — | Siemens Simatic Wincc Unified PC Runtime | 9/6/2026 | 23/7/2026 | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /archive1.php. Performing a manipulation of the argument sy results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive2.php. Such manipulation of the argument sy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Pendiente de análisis | Crítica (9.2) | 0.38% | — | SqliteAIMicrosoft Windows C RuntimeAI | 4/6/2026 | 22/7/2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command… | |
| Analizada | Alta (7.5) | 0.46% | — | Shopify React-routerShopify Remix-run/server-runtime | 2/6/2026 | 21/7/2026 | React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation… |