Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.25% | — | Aider-chatAI | 4/9/2026 | 10/9/2026 | aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user… | |
| Aplazada | Alta (8.1) | 0.43% | — | Raider SpiritAI | 17/6/2026 | 30/9/2026 | Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions. | |
| Aplazada | Baja (2.1) | 0.21% | — | Aider-ai AiderAI | 31/5/2026 | 22/7/2026 | A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.20% | — | Aider-ai AiderAI | 31/5/2026 | 22/7/2026 | A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (2.1) | 0.24% | — | Aider-ai AiderAI | 31/5/2026 | 22/7/2026 | A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.23% | — | Aider-ai AiderAI | 31/5/2026 | 22/7/2026 | A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism failure. The attack may be launched remotely. The exploit is publicly available… | |
| Aplazada | Media (5.5) | 2.1% | — | Eiliyaabedini Aider-mcpAI | 28/4/2026 | 24/7/2026 | A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an unknown function of the file aider_mcp.py of the component code_with_ai. The manipulation of the argument working_dir/editable_files leads to command injection. The attack may be initiated remotely.… | |
| Aplazada | Media (5.5) | 2.1% | — | Disler Aider-mcp-serverAI | 27/4/2026 | 17/6/2026 | A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes command injection.… | |
| Aplazada | Alta (8.6) | 0.32% | — | MD Yeasin UL Haider URL ShortenerAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Crítica (9.8) | 0.50% | — | MD Yeasin UL Haider URL Shortener Exact-linksAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Crítica (9.3) | 0.37% | — | MD Yeasin UL Haider URL Shortener Exact-linksAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows SQL Injection.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Media (5.4) | 0.18% | — | MD Yeasin UL Haider URL Shortener Exact LinksAI | 4/7/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Modificada | Media (4.3) | 2.4% | — | TOM Braider Count PER DAY | 15/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter. | |
| Modificada | Media (5) | 23% | — | Count PER DAY Project Count PER DAYTOM Braider Count PER DAY | 20/1/2012 | 16/6/2026 | Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter. | |
| Modificada | Media (4.3) | 5.3% | — | TOM Braider Count PER DAY | 20/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter. | |
| Modificada | Media (5.8) | 1.8% | — | Idefense Comraider | 4/11/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateFolder and (2) Copy methods. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer. | |
| Modificada | Media (4.3) | 0.84% | — | PhpraiderSimple Machines Phpraider | 24/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.5% | — | Phpraider | 18/6/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in authentication/smf/smf.functions.php in Simple Machines phpRaider 1.0.6 and 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[smf_path] parameter. | |
| Modificada | Alta (10) | 5.0% | — | Phpraider | 28/5/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpraider | 26/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in phpRaider 1.0.0 rc8 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) type parameter. |