Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.32% | — | Nightwolf Penetration Testing TrackingAI | 31/3/2025 | 17/6/2026 | Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references. | |
| Aplazada | Media (5.4) | 0.15% | — | Misteraon Simple Trackback DisablerAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in misteraon Simple Trackback Disabler simple-trackback-disabler allows Cross Site Request Forgery.This issue affects Simple Trackback Disabler: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.29% | — | PitchforkAIRackAI | 27/3/2025 | 17/6/2026 | Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with Rack 3. The issue was fixed in Pitchfork release 0.11.0. No known workarounds are available. | |
| Aplazada | Alta (7.6) | 0.60% | — | Wpdever Cart-tracking-for-woocommerceAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce cart-tracking-for-woocommerce allows SQL Injection.This issue affects Cart tracking for WooCommerce: from n/a through <= 1.0.16. | |
| Aplazada | Alta (7.1) | 0.39% | — | MAX K UTM Tags Tracking FOR Contact Form 7AI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max K UTM tags tracking for Contact Form 7 cf7-utm-tracking allows Reflected XSS.This issue affects UTM tags tracking for Contact Form 7: from n/a through <= 2.1. | |
| Aplazada | Media (6.1) | 0.24% | — | TrmtrackerAI | 25/3/2025 | 17/6/2026 | The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality and integrity of the system. | |
| Aplazada | Media (6.1) | 0.24% | — | TrmtrackerAI | 25/3/2025 | 17/6/2026 | A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning. | |
| Aplazada | Media (6.5) | 0.27% | — | TrmtrackerAI | 25/3/2025 | 17/6/2026 | The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website. | |
| Aplazada | Alta (7.1) | 0.18% | — | Proranktracker PRO Rank TrackerAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ProRankTracker Pro Rank Tracker proranktracker allows Stored XSS.This issue affects Pro Rank Tracker: from n/a through <= 1.0.0. | |
| Modificada | Alta (7.5) | 1.2% | — | Rack | 10/3/2025 | 17/6/2026 | Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly. The vulnerability occurs because… | |
| Analizada | Baja (3.5) | 0.32% | — | Tahminajannat URL Shortener | Conversion Tracking | AB Testing | Woocommerce | 9/3/2025 | 17/6/2026 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Analizada | Media (4.3) | 0.17% | — | Tahminajannat URL Shortener | Conversion Tracking | AB Testing | Woocommerce | 9/3/2025 | 17/6/2026 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks | |
| Analizada | Media (6.1) | 0.32% | — | Tahminajannat URL Shortener | Conversion Tracking | AB Testing | Woocommerce | 6/3/2025 | 17/6/2026 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (6.9) | 0.76% | — | Rack | 4/3/2025 | 17/6/2026 | Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13,… | |
| Aplazada | Alta (7.1) | 0.37% | — | Mndpsingh287 Track-page-scrollAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 Track Page Scroll track-page-scroll allows Reflected XSS.This issue affects Track Page Scroll: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.2) | 0.36% | — | E-kent Pallium Vehicle TrackingAI | 27/2/2025 | 17/6/2026 | Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This issue affects Pallium Vehicle Tracking: before 17.10.2024. | |
| Aplazada | Media (4.4) | 0.19% | — | Owasp Dependency-trackAI | 24/2/2025 | 17/6/2026 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize notification templates. Templates are evaluated using the Pebble template engine. Pebble supports… | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Crítica (9.8) | 0.59% | — | Wecantrack Affiliate Links | 18/2/2025 | 17/6/2026 | The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export. This makes it possible for unauthenticated attackers to inject a PHP Object. No… | |
| Analizada | Media (4.7) | 0.36% | — | Stephencarr Track Logins | 17/2/2025 | 17/6/2026 | The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Aplazada | Alta (7.1) | 0.25% | — | Tahminajannat URL Shortener Conversion Tracking AB Testing WoocommerceAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tahminajannat URL Shortener | Conversion Tracking | AB Testing | WooCommerce easy-broken-link-checker allows Reflected XSS.This issue affects URL Shortener | Conversion Tracking | AB Testing | WooCommerce: from n/a… | |
| Modificada | Media (5.7) | 1.2% | — | Rack | 12/2/2025 | 17/6/2026 | Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content into logs. When a… | |
| Modificada | Crítica (9.8) | 0.50% | — | Phpgurukul Daily Expense Tracker System | 12/2/2025 | 17/6/2026 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter. | |
| Modificada | Crítica (9.8) | 0.50% | — | Phpgurukul Daily Expense Tracker System | 12/2/2025 | 17/6/2026 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter. | |
| Analizada | Media (5.3) | 0.46% | — | 1000projects Attendance Tracking Management System | 12/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file /admin/chart1.php. The manipulation of the argument course_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |