Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 505 respecto a la semana anterior
Críticas / altas1460▲ 59 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
5682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.32% | — | Roocode ROO Code | 5/9/2025 | 17/6/2026 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker with write access to the workspace to trick the extension into reading files that were intended to be… | |
| Analizada | Crítica (9.8) | 0.53% | — | Roocode ROO Code | 5/9/2025 | 17/6/2026 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration files (.code-workspace) are not protected in the same way as the .vscode folder. If the agent was configured to auto-approve file writes, an… | |
| Analizada | Alta (8.1) | 0.44% | — | Roocode ROO Code | 5/9/2025 | 17/6/2026 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were not handled correctly. If the agent was configured to auto-approve execution of certain commands, an… | |
| Analizada | Crítica (9.9) | 0.80% | 💥 PoC | Roocode ROO Code | 5/9/2025 | 30/9/2026 | Roo Code es un agente de codificación autónomo impulsado por IA que reside en los editores de los usuarios. En las versiones 3.26.6 e inferiores, un flujo de trabajo de Github utilizaba metadatos de solicitudes de extracción no saneados en un contexto privilegiado, lo que permitía a un atacante crear una entrada… | |
| Aplazada | Media (6.5) | 0.17% | — | Reubenthiessen Translate This Gtranslate ShortcodeAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reubenthiessen Translate This gTranslate Shortcode translate-this-google-translate-web-element-shortcode allows Stored XSS.This issue affects Translate This gTranslate Shortcode: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.17% | — | ALI Aghdam Aparat Video ShortcodeAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Aghdam Aparat Video Shortcode aparat-shortcode allows Stored XSS.This issue affects Aparat Video Shortcode: from n/a through <= 0.2.4. | |
| Aplazada | Alta (7.1) | 0.12% | — | Kaizencoders Enable LatexAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Enable Latex enable-latex allows Stored XSS.This issue affects Enable Latex: from n/a through <= 1.2.16. | |
| Aplazada | Alta (7.1) | 0.24% | — | Kaizencoders Table OF ContentAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Table of content content-table allows Stored XSS.This issue affects Table of content: from n/a through <= 1.5.3.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Ablancodev Woocommerce Notify Updated ProductAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS.This issue affects Woocommerce Notify Updated Product: from n/a through <= 1.6. | |
| Aplazada | Media (6.5) | 0.22% | — | Codemstory Mshop-naver-talktalkAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemstory 코드엠샵 소셜톡 mshop-naver-talktalk allows Stored XSS.This issue affects 코드엠샵 소셜톡: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Codestag StagtoolsAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ram Ratan Maurya Stagtools stagtools allows Stored XSS.This issue affects Stagtools: from n/a through <= 2.3.8. | |
| Aplazada | Media (5.9) | 0.22% | — | Wpcodeus Ultimate Client DashAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CodeUs Ultimate Client Dash ulimate-client-dash allows Stored XSS.This issue affects Ultimate Client Dash: from n/a through <= 4.7. | |
| Analizada | Baja (2.1) | 0.49% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.49% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the argument uimage can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2) | 0.29% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument msg results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2) | 0.24% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Baja (2.1) | 0.41% | — | Campcodes Sales AND Inventory System | 3/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the argument page can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.41% | — | Campcodes Sales AND Inventory System | 3/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Such manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly… | |
| Analizada | Baja (1.9) | 0.29% | — | Code-projects POS Pharmacy System | 3/9/2025 | 17/6/2026 | A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /main/products.php. This manipulation of the argument product_code/gen_name/product_name/supplier causes cross site scripting. The attack can be initiated remotely. The exploit has been made available… | |
| Analizada | Baja (2) | 0.46% | — | Campcodes Online Recruitment Management System | 3/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of the file /admin/index.php. The manipulation of the argument page results in file inclusion. It is possible to launch the attack remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (5.9) | 0.19% | — | Rbaer Simple Matomo Tracking CodeAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Iuliacazan Latest Post ShortcodeAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Stored XSS.This issue affects Latest Post Shortcode: from n/a through <= 14.0.3. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly… |