Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▲ 218 respecto a la semana anterior
Críticas / altas1330▼ 103 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
5675 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.39% | — | Campcodes Supplier Management System | 23/11/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.3) | 0.30% | — | Codepeople Booking Calendar Contact FormAI | 22/11/2025 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (8.1) | 0.66% | — | Roocode ROO Code | 21/11/2025 | 17/6/2026 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7. | |
| Aplazada | Media (4.3) | 0.19% | — | Tychesoftwares Arconix ShortcodesAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arconix Shortcodes: from n/a through <= 2.1.18. | |
| Aplazada | Media (5.3) | 0.25% | — | Ayecode UserswpAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47. | |
| Aplazada | Media (6.4) | 0.18% | — | Shortcode FOR Google Street ViewAI | 21/11/2025 | 8/10/2026 | El plugin Shortcode for Google Street View para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'streetview' en todas las versiones hasta la 0.5.7, inclusive. Esto se debe a una sanitización de entrada insuficiente y un escape de salida en el atributo 'id'. Esto hace posible que… | |
| Aplazada | Media (6.4) | 0.23% | — | Wpsite ShortcodeAI | 21/11/2025 | 8/10/2026 | El plugin WPSite Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de shortcode 'format' en el shortcode wpsite_y y el atributo 'before' en el shortcode wpsite_postauthor en todas las versiones hasta la 1.2, inclusive. Esto se debe a una sanitización de entrada insuficiente… | |
| Aplazada | Media (6.4) | 0.22% | — | Pollcaster Shortcode PluginAI | 21/11/2025 | 7/10/2026 | El plugin de shortcode Pollcaster para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'height' en el shortcode 'pollcaster' en todas las versiones hasta la 1.0, e incluyendo esta. Esto se debe a una sanitización de entrada y un escape de salida insuficientes en los atributos… | |
| Aplazada | Media (6.4) | 0.22% | — | Padlet ShortcodeAI | 21/11/2025 | 7/10/2026 | El plugin Padlet Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'key' en el shortcode 'wallwisher' en todas las versiones hasta la 1.3, inclusive. Esto se debe a una sanitización de entrada insuficiente y un escape de salida inadecuado en los atributos proporcionados… | |
| Aplazada | Media (6.4) | 0.18% | — | Bulma ShortcodesAI | 21/11/2025 | 7/10/2026 | El plugin Bulma Shortcodes para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de shortcode 'type' en el shortcode bulma-notification en todas las versiones hasta la 1.0, inclusive. Esto se debe a una sanitización de entrada insuficiente y un escape de salida inadecuado. Esto hace… | |
| Aplazada | Media (6.4) | 0.18% | — | Surbma Minicrm ShortcodeAI | 21/11/2025 | 7/10/2026 | El plugin Surbma | MiniCRM Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de shortcode 'id' del shortcode 'minicrm' en todas las versiones hasta la 2.0, inclusive. Esto se debe a una sanitización de entrada insuficiente y un escape de salida insuficiente. Esto permite… | |
| Aplazada | Media (6.4) | 0.18% | — | Brighttalk Wordpress ShortcodeAI | 21/11/2025 | 7/10/2026 | El plugin BrightTALK WordPress Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través del atributo 'format' del shortcode en el shortcode brighttalk-time en todas las versiones hasta la 2.4.0, inclusive. Esto se debe a una sanitización de entrada insuficiente y un escape de salida… | |
| Aplazada | Media (6.4) | 0.18% | — | Tips ShortcodeAI | 21/11/2025 | 7/10/2026 | El plugin Tips Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'tip' en todas las versiones hasta la 0.2.1, inclusive. Esto se debe a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes autenticados, con acceso de nivel de… | |
| Aplazada | Media (6.4) | 0.18% | — | Shortcodes BootstrapAI | 21/11/2025 | 7/10/2026 | El plugin Shortcodes Bootstrap para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'type' en el shortcode [notification] en todas las versiones hasta la 1.1, inclusive. Esto se debe a la falta de saneamiento de entrada y escape de salida. Esto permite a atacantes autenticados, con… | |
| Aplazada | Media (6.4) | 0.22% | — | Display Pages ShortcodeAI | 21/11/2025 | 7/10/2026 | El plugin Display Pages Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'column_count' en el shortcode [display-pages] en todas las versiones hasta la 1.1, inclusive. Esto se debe a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes… | |
| Analizada | Alta (8.7) | 0.55% | — | Anthropic Claude Code | 21/11/2025 | 17/6/2026 | Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31. | |
| Modificada | Alta (8) | 0.56% | — | Microsoft Visual Studio Code | 20/11/2025 | 17/6/2026 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Online Beauty Parlor Management System | 20/11/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and… | |
| Analizada | Baja (2) | 0.38% | — | Campcodes Supplier Management System | 20/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument txtProductName leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be… | |
| Modificada | Baja (2) | 0.34% | — | Campcodes Retro Basketball Shoes Online Store | 20/11/2025 | 17/6/2026 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and… | |
| Analizada | Alta (7.3) | 0.20% | — | Campcodes Online Hospital Management System | 19/11/2025 | 17/6/2026 | Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username. | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit… | |
| Modificada | Baja (2) | 0.36% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely.… | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (8.8) | 0.34% | — | Devcode OpenstamanagerAI | 19/11/2025 | 17/6/2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an… |