Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

5675 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.69%—Anthropic Claude Code3/12/202517/6/2026
Claude Code es una herramienta de codificación agéntica. Versiones anteriores a la 1.0.93, debido a errores en el análisis de comandos de shell relacionados con $IFS y flags CLI cortos, era posible eludir la validación de solo lectura de Claude Code y desencadenar la ejecución de código arbitrario. Explotar esto de…
AplazadaMedia (6.4)0.23%—Cssigniter ShortcodesAI3/12/202517/6/2026
The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaMedia (6.4)0.18%—Redhat Codeready WorkspacesAI2/12/202517/6/2026
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can…
AplazadaMedia (6.5)0.16%—Tychesoftwares Arconix ShortcodesAI1/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.20.
AnalizadaMedia (6.5)0.38%—Tempus-ex Hello-video-codec1/12/202517/6/2026
Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaMedia (5.9)0.35%—Codesys Control Runtime SystemAI1/12/202517/6/2026
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
AnalizadaAlta (7.5)0.39%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+131/12/202517/6/2026
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
AnalizadaAlta (7.8)0.15%—Codesys1/12/202517/6/2026
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
AplazadaMedia (5.3)0.28%—AYS Code AI Chatbot With Chatgpt AND Content GeneratorAI27/11/202517/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.
AnalizadaMedia (4.3)0.29%—Opencode Ussd Gateway26/11/202517/6/2026
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.
AnalizadaMedia (6.5)0.34%—Opencode Ussd Gateway26/11/202517/6/2026
Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information.
AnalizadaMedia (6.1)0.27%—Opencode Ussd Gateway26/11/202517/6/2026
A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.
AnalizadaCrítica (9.8)0.45%—Opencode Ussd Gateway26/11/202517/6/2026
OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.
AnalizadaCrítica (9.8)0.45%—Opencode Ussd Gateway26/11/202517/6/2026
OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.
ModificadaAlta (7.7)0.32%—Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+2526/11/202531/8/2026
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,…
AnalizadaAlta (7.4)0.33%—Bytecodealliance Webassembly Micro Runtime25/11/202517/6/2026
WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is…
AnalizadaMedia (5.5)0.19%—Bytecodealliance Webassembly Micro Runtime25/11/202517/6/2026
WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4.
AnalizadaMedia (6.5)0.16%—Magewell Ultra Encode Hdmi FirmwareMagewell Ultra Encode SDI FirmwareMagewell Ultra Encode Hdmi Plus FirmwareMagewell Ultra Encode SDI Plus Firmware+124/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
AnalizadaBaja (2.1)0.31%—Code-projects Library System24/11/20258/10/2026
Se determinó una vulnerabilidad en code-projects Library System 1.0. Se ve afectada una función desconocida del archivo /mail.php. Esta manipulación del argumento ID causa inyección SQL. El ataque puede iniciarse remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado.
AnalizadaBaja (2.1)0.31%—Code-projects Library System24/11/20258/10/2026
Una vulnerabilidad fue encontrada en code-projects Library System 1.0. Esto impacta una función desconocida del archivo /return.php. La manipulación del argumento ID resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit ha sido hecho público y podría ser usado.
AnalizadaMedia (5.5)0.39%—Code-projects Library System24/11/20258/10/2026
Una vulnerabilidad ha sido encontrada en code-projects Library System 1.0. Esto afecta una función desconocida del archivo /index.php del componente Login. La manipulación del argumento Username conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado al público y puede ser…
AplazadaMedia (6.4)0.18%—Shortcodes UltimateAI23/11/20258/10/2026
El plugin WP Shortcodes Plugin - Shortcodes Ultimate para WordPress es vulnerable a falsificación de petición del lado del servidor en todas las versiones hasta la 7.4.5, inclusive, a través de la función su_shortcode_csv_table. Esto permite a atacantes autenticados, con acceso de nivel de Administrador o superior,…
AnalizadaMedia (5.5)0.39%—Campcodes Online Polling System23/11/202517/6/2026
A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.5)0.39%—Campcodes Online Polling System23/11/202517/6/2026
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
ModificadaMedia (5.5)0.39%—Campcodes School File Management System23/11/202517/6/2026
A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.