Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | Kevonadonis WP AbstractsAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows PHP Local File Inclusion.This issue affects WP Abstracts: from n/a through <= 2.7.4. | |
| Aplazada | Media (4.9) | 0.37% | — | Email TrackerAI | 22/10/2025 | 17/6/2026 | The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (5.4) | 0.35% | — | Cobblestonesoftware Enterprise Contract Management PortalAI | 17/10/2025 | 5/7/2026 | CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code. NOTE: the Supplier reports that this is "Present only in an obsolete, unsupported version no longer in circulation." | |
| Aplazada | Crítica (9.8) | 0.37% | — | Cats Information Technology Software Development Technologies Aykome License Tracking SystemAI | 13/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows SQL Injection. This issue affects Aykome License Tracking System: before Version dated 06.10.2025. | |
| Aplazada | Media (6.9) | 0.36% | — | Piextract Soop-clmAI | 13/10/2025 | 17/6/2026 | SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information. | |
| Aplazada | Alta (8.6) | 0.58% | — | Piextract Soop-clmAI | 13/10/2025 | 17/6/2026 | SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server. | |
| Aplazada | Media (4.7) | 0.28% | — | Owasp Dependency-trackAI | 7/10/2025 | 17/6/2026 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.13.5, Dependency-Track may send credentials meant for a private NuGet repository to `api.nuget.org` via the HTTP `Authorization` header, and may disclose names and… | |
| Aplazada | Baja (2) | 0.23% | — | Axosoft Scrum AND BUG TrackingAI | 5/10/2025 | 17/6/2026 | A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing of the component Add Work Item Page. The manipulation of the argument Title results in csv injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was… | |
| Aplazada | Alta (8.7) | 1.3% | 💥 Exploit | TraccarAI | 2/10/2025 | 17/6/2026 | Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the… | |
| Aplazada | Alta (7.1) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-easy-stripe-paypal-donations allows Stored XSS.This issue affects WP Attractive Donations System: from n/a through < 1.29. | |
| Aplazada | Alta (8.8) | 0.36% | — | Time TrackerAI | 11/9/2025 | 17/6/2026 | The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_function' and 'tt_delete_record_function' functions in all versions up to, and including, 3.1.0. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2) | 0.29% | — | Rems Personal Time Tracker | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.9) | 0.19% | — | Rbaer Simple Matomo Tracking CodeAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0. | |
| Analizada | Media (4.2) | 0.32% | 💥 PoC | Donbermoy Android Corona Virus Tracker APP FOR India | 3/9/2025 | 17/6/2026 | The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes… | |
| Aplazada | Baja (2.3) | 0.33% | — | Tracing-subscriberAI | 29/8/2025 | 17/6/2026 | tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when… | |
| Analizada | Baja (2.4) | 0.26% | 💥 PoC | Meitrack T366l-g Firmware | 28/8/2025 | 25/9/2026 | Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive… | |
| Aplazada | Media (5.9) | 0.22% | — | Vikingjs Goal Tracker FOR PatreonAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon goal-tracker-for-patreon allows Stored XSS.This issue affects Goal Tracker for Patreon: from n/a through <= 0.4.6. | |
| Aplazada | Media (5.3) | 0.22% | — | Aftership TrackingAIAftership Woocommerce TrackingAI | 27/8/2025 | 17/6/2026 | Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AfterShip Tracking: from n/a through <= 1.17.17. | |
| Analizada | Media (5.4) | 0.28% | — | Jetbrains Youtrack | 20/8/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content | |
| Aplazada | Alta (7.2) | 0.41% | — | Adform Site TrackingAI | 19/8/2025 | 17/6/2026 | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1). | |
| Analizada | Baja (1.9) | 0.26% | — | Aftership Package Tracker | 19/8/2025 | 17/6/2026 | A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the file AndroidManifest.xml of the component com.aftership.AfterShip. The manipulation leads to improper export of android application components. The attack must be… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Trace Analyzer AND CollectorAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.1) | 0.26% | — | Jetbrains Youtrack | 28/7/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions | |
| Aplazada | Media (4.4) | 0.17% | — | Lakesidesoftware SystrackerAI | 27/7/2025 | 17/6/2026 | LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malicious DLL to that directory with arbitrary code. This malicious… | |
| Aplazada | Media (5.3) | 0.29% | — | Real-time BUS Tracking SystemAI | 23/7/2025 | 17/6/2026 | Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) condition may be caused by an attacker who can log in to the administrative page of the affected product. |