Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

5682 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.33%—Iocoder Ruoyi-vue-pro12/9/202517/6/2026
A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The…
AnalizadaBaja (2.1)0.33%—Iocoder Ruoyi-vue-pro12/9/202517/6/2026
A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed…
ModificadaCrítica (9.8)0.92%💥 PoCMicrosoft Visual Studio Code12/9/202517/6/2026
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
AnalizadaBaja (2.1)0.33%—Iocoder Yudao-cloud12/9/202517/6/2026
A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument ids/newOwnerUserId can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and…
AnalizadaBaja (2.1)0.33%—Iocoder Yudao-cloud12/9/202530/9/2026
Una vulnerabilidad fue detectada en YunaiV yudao-cloud hasta 2025.09. Este problema afecta a algún procesamiento desconocido del archivo /crm/receivable/submit. La manipulación del argumento ID resulta en autorización indebida. El ataque puede ser ejecutado remotamente. El exploit es ahora público y puede ser usado.…
AplazadaMedia (6.4)0.24%—Codeboxr CBX MAPAI11/9/202517/6/2026
The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup heading and location address parameters in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.24%—Azurecurve BbcodeAI11/9/202517/6/2026
The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaBaja (2)0.25%—Lokibhardwaj Php-code-for-unlimited-file-uploadAI11/9/202517/6/2026
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made…
AnalizadaAlta (8.7)0.55%—Anthropic Claude Code10/9/202517/6/2026
Claude Code es una herramienta de codificación agéntica. Al iniciar, Claude Code ejecutó un comando plantillado con 'git config user.email'. Antes de la versión 1.0.105, un correo electrónico de usuario configurado maliciosamente en git podría utilizarse para desencadenar la ejecución de código arbitrario antes de que…
AnalizadaAlta (8.7)0.55%—Anthropic Claude Code10/9/202517/6/2026
Claude Code es una herramienta de codificación agéntica. Debido a un error en el análisis de comandos, las versiones anteriores a la 1.0.105 eran vulnerables a una elusión del aviso de confirmación de Claude Code para desencadenar la ejecución de un comando no confiable. Explotar esto de forma fiable requiere la…
AplazadaAlta (7.6)0.28%—Presstigers ZIP Code Based Content ProtectionAI9/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue affects ZIP Code Based Content Protection: from n/a through <= 1.0.0.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System8/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to…
AnalizadaMedia (5.5)0.42%—Campcodes Online Loan Management System8/9/202517/6/2026
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and…
AnalizadaMedia (5.5)0.48%—Campcodes Online Loan Management System8/9/202517/6/2026
A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalizadaCrítica (9.8)2.2%—Codeceptjs8/9/202517/6/2026
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.
AplazadaAlta (7.4)0.28%—Microsoft Windows Defender Application ControlAIMicrosoft Hypervisor-protected Code IntegrityAI8/9/202517/6/2026
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System6/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaBaja (2.1)0.42%—Campcodes Grocery Sales AND Inventory System6/9/202517/6/2026
A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /index.php. The manipulation of the argument page results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.
AnalizadaMedia (5.5)0.48%—Campcodes Grocery Sales AND Inventory System6/9/202517/6/2026
A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.48%—Campcodes Grocery Sales AND Inventory System6/9/202517/6/2026
A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_receiving. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to…
AnalizadaAlta (8.1)0.38%—Coder6/9/202517/6/2026
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a user when a workspace is started. It is…
AnalizadaAlta (7.8)0.21%—Roocode ROO Code6/9/202517/6/2026
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm install is included in that list. Because npm install executes lifecycle scripts, if a repository’s…
AplazadaMedia (6.5)0.34%—Ayecode UserswpAI6/9/202517/6/2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the user…