Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.41%—Adform Site TrackingAI19/8/202517/6/2026
The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).
AnalizadaBaja (1.9)0.26%—Aftership Package Tracker19/8/202517/6/2026
A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the file AndroidManifest.xml of the component com.aftership.AfterShip. The manipulation leads to improper export of android application components. The attack must be…
AnalizadaMedia (6.1)0.26%—Jetbrains Youtrack28/7/202517/6/2026
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
AplazadaMedia (4.4)0.17%—Lakesidesoftware SystrackerAI27/7/202517/6/2026
LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malicious DLL to that directory with arbitrary code. This malicious…
AplazadaMedia (5.3)0.29%—Real-time BUS Tracking SystemAI23/7/202517/6/2026
Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) condition may be caused by an attacker who can log in to the administrative page of the affected product.
AplazadaMedia (5.4)0.15%—Lenovo Trackpoint Quick MenuAI17/7/202517/6/2026
A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.
AnalizadaAlta (7.6)0.29%—Jetbrains Youtrack15/7/202517/6/2026
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
AplazadaCrítica (9.8)0.43%—Mavi Yesil Software Guest Tracking SoftwareAI27/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection. This issue affects Guest Tracking Software. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The…
AplazadaAlta (7.1)0.13%—Ethoseo Track EverythingAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything track-everything allows Stored XSS.This issue affects Track Everything: from n/a through <= 2.0.1.
AnalizadaMedia (5.4)0.19%—Blakelong Tournament Bracket Generator26/6/202517/6/2026
The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaAlta (7.1)0.26%—Track Analyze AND Optimize BY WP TAOAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Track, Analyze & Optimize by WP Tao wp-tao allows Reflected XSS.This issue affects Track, Analyze & Optimize by WP Tao: from n/a through <= 1.3.
AnalizadaAlta (7.3)0.27%—Etracker13/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.
AplazadaAlta (7.6)0.45%—Sinotrack Device Management InterfaceAI12/6/202517/6/2026
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A…
AnalizadaMedia (6.6)0.56%—Rack4/6/202517/6/2026
Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to the previous security issue CVE-2022-44571. Carefully crafted input can cause Content-Disposition…
AnalizadaMedia (5.3)0.41%—Phpgurukul Daily Expense Tracker System4/6/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /expense-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.43%—Phpgurukul Daily Expense Tracker System31/5/202517/6/2026
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /expense-yearwise-reports-detailed.php. The manipulation of the argument todate leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (6.1)0.24%—Bestpractical Request Tracker28/5/202517/6/2026
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
AnalizadaMedia (6.1)0.24%—Bestpractical Request Tracker28/5/202517/6/2026
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
ModificadaMedia (6.1)0.31%—Bestpractical Request Tracker28/5/202517/6/2026
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
AnalizadaAlta (7.5)0.40%—Events LOG Track Project Events LOG Track21/5/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, from 4.0.0 before 4.0.2.
AnalizadaAlta (7.5)0.41%—Jetbrains Youtrack20/5/202517/6/2026
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
AnalizadaMedia (5.3)0.37%—Jetbrains Youtrack20/5/202517/6/2026
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
AnalizadaMedia (6.9)0.51%—Phpgurukul Daily Expense Tracker System19/5/202517/6/2026
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched…
AnalizadaMedia (6.9)0.58%—Phpgurukul Daily Expense Tracker System19/5/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Daily Expense Tracker System 1.1. This affects an unknown part of the file /expense-datewise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (6.9)0.58%—Phpgurukul Daily Expense Tracker System19/5/202517/6/2026
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been…