Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

5676 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.34%—Devcode OpenstamanagerAI19/11/202517/6/2026
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission level, to execute arbitrary SQL queries. By manipulating the display parameter in an API request, an…
AnalizadaAlta (7.5)0.41%—Lanol Filecodebox19/11/202517/6/2026
A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by faking X-Real-IP and X-Forwarded-For HTTP headers. This can enable attackers to perform DoS attacks or brute force share codes.
AnalizadaMedia (5.4)0.17%—Lanol Filecodebox19/11/202517/6/2026
A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try…
AnalizadaAlta (7.5)0.53%—Lanol Filecodebox19/11/202517/6/2026
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows…
AnalizadaAlta (7.7)0.51%💥 PoCAnthropic Claude Code19/11/202517/6/2026
Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the user accepted the startup trust dialog. Exploiting this would have required a user to start Claude…
AnalizadaAlta (8.7)2.8%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workflow handled by AudioCodes_files/ActivateLicense.php. When a license file is uploaded, the application derives a new filename by combining a…
AnalizadaAlta (8.7)3.4%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality implemented by AudioCodes_files/TestFax.php. When a fax "send" test is requested, the application builds a faxsender command line using…
AnalizadaAlta (8.5)0.20%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT…
AnalizadaAlta (8.5)0.20%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are requested through…
AnalizadaAlta (8.7)0.53%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via the download.php script. The endpoint exposes a file download mechanism that lacks access control, allowing remote, unauthenticated users to request files stored on the…
AnalizadaMedia (6.9)0.46%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the…
AnalizadaCrítica (9.3)1.1%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates the directory if it…
AnalizadaCrítica (9.3)0.71%—Audiocodes FAX ServerAudiocodes Interactive Voice Response19/11/202517/6/2026
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files/utils/IVR/diagram/ajaxScript.php. The saveScript action writes attacker-supplied data directly to…
AplazadaMedia (5.5)0.30%—Codehub666 94listAI19/11/202517/6/2026
A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted element is the function Login of the file /function.php. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be…
AplazadaAlta (8)0.36%—Codesnippets Code SnippetsAI19/11/202517/6/2026
The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable…
AnalizadaMedia (5.7)0.20%—Sencore Decoder-ccv2 FirmwareSencore Smp100 FirmwareSencore En2sdi-2hd Firmware18/11/202517/6/2026
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint…
AnalizadaMedia (5.5)0.39%—Itsourcecode Web-based Internet Laboratory Management System17/11/20257/10/2026
Una vulnerabilidad fue encontrada en itsourcecode Web-Based Internet Laboratory Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /subject/controller.php. La manipulación resulta en inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido hecho…
AnalizadaMedia (5.5)0.39%—Itsourcecode Web-based Internet Laboratory Management System17/11/20257/10/2026
Una vulnerabilidad ha sido encontrada en itsourcecode Web-Based Internet Laboratory Management System 1.0. Afecta a una función desconocida del archivo /settings/controller.php. La manipulación conduce a inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado al público y puede ser…
ModificadaMedia (5.5)0.39%—Itsourcecode Web-based Internet Laboratory Management System17/11/20257/10/2026
Se ha encontrado un fallo en itsourcecode Web-Based Internet Laboratory Management System 1.0. Esto afecta a una función desconocida del archivo /user/controller.PHP. La ejecución de una manipulación puede conducir a una inyección SQL. El ataque puede realizarse de forma remota. El exploit ha sido publicado y puede…
ModificadaMedia (5.5)0.41%—Itsourcecode Web-based Internet Laboratory Management System17/11/20257/10/2026
Se detectó una vulnerabilidad en itsourcecode Web-Based Internet Laboratory Management System 1.0. Esto afecta a una función desconocida del archivo /enrollment/controller.php. Realizar una manipulación resulta en inyección SQL. El ataque puede ser llevado a cabo de forma remota. El exploit ahora es público y puede…
AnalizadaMedia (5.5)0.39%—Itsourcecode Web-based Internet Laboratory Management System17/11/20257/10/2026
Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Web-Based Internet Laboratory Management System 1.0. El elemento afectado es una función desconocida del archivo /course/controller.php. Dicha manipulación conduce a inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido divulgado…
ModificadaMedia (5.5)0.39%—Campcodes Supplier Management System17/11/20257/10/2026
Se encontró una vulnerabilidad en Campcodes Supplier Management System 1.0. Esto afecta una parte desconocida del archivo /manufacturer/confirm_order.php. Realizar una manipulación del argumento ID resulta en inyección SQL. El ataque puede iniciarse remotamente. El exploit se ha hecho público y podría ser usado.
ModificadaMedia (5.5)0.38%—Codeastro Simple Inventory System17/11/20257/10/2026
Una vulnerabilidad se determinó en CodeAstro Simple Inventory System 1.0. El elemento afectado es una función desconocida del archivo /index.php del componente Login. La ejecución de una manipulación del argumento Username puede conducir a inyección SQL. El ataque puede lanzarse remotamente. El exploit ha sido…
ModificadaBaja (2.1)0.31%—Campcodes School Fees Payment Management System17/11/20257/10/2026
Se ha identificado una debilidad en Campcodes School Fees Payment Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /ajax.php?action=delete_fees. La ejecución de una manipulación del argumento ID puede conducir a inyección SQL. El ataque puede realizarse de forma remota.…
ModificadaBaja (2.1)0.31%—Campcodes School Fees Payment Management System17/11/20257/10/2026
Una falla de seguridad ha sido descubierta en Campcodes School Fees Payment Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /ajax.PHP?action=delete_payment. Realizar una manipulación del argumento ID resulta en inyección SQL. El ataque es posible de ser llevado a…