Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Orlandolac Facilita Form TrackerAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker facilita-form-tracker allows Stored XSS.This issue affects Facilita Form Tracker: from n/a through <= 1.0. | |
| Analizada | Media (5.9) | 0.26% | — | Data443 Tracking Code Manager | 30/1/2025 | 17/6/2026 | The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. | |
| Analizada | Alta (7.8) | 0.22% | — | Jetbrains Youtrack | 21/1/2025 | 17/6/2026 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | |
| Analizada | Media (5.5) | 0.60% | — | Jetbrains Youtrack | 21/1/2025 | 17/6/2026 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | |
| Analizada | Media (5.3) | 0.55% | — | 1000projects Attendance Tracking Management System | 17/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.37% | — | Alex Furr Progress TrackerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr Progress Tracker progress-tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through <= 0.9.3. | |
| Aplazada | Media (6.4) | 0.32% | — | TrackserverAI | 11/1/2025 | 17/6/2026 | The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.32% | — | Opentracker AnalyticsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentracker Analytics opentracker-analytics allows Reflected XSS.This issue affects Opentracker Analytics: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.41% | — | Mimo Woocommerce Order TrackingAI | 9/1/2025 | 17/6/2026 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add, update, and… | |
| Analizada | Media (5.3) | 1.1% | — | RackDebian Linux | 9/1/2025 | 17/6/2026 | There is a denial of service vulnerability in the header parsing component of Rack. | |
| Aplazada | Media (5.5) | 0.17% | — | AAT Another Activity TrackerAI | 6/1/2025 | 17/6/2026 | AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to data exfiltration from malicious apps installed on the same device. | |
| Analizada | Media (5.3) | 0.45% | — | 1000projects Attendance Tracking Management System | 30/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been classified as critical. Affected is the function attendance_report of the file /admin/report.php. The manipulation of the argument course_id leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.72% | — | 1000projects Attendance Tracking Management System | 29/12/2024 | 17/6/2026 | A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/attendance_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.61% | — | 1000projects Attendance Tracking Management System | 26/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of the file /admin/admin_action.php. The manipulation of the argument admin_user_name leads to sql injection. The attack may be initiated remotely.… | |
| Analizada | Media (6.9) | 0.70% | — | 1000projects Attendance Tracking Management System | 26/12/2024 | 17/6/2026 | A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/student_action.php. The manipulation of the argument student_id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.60% | — | 1000projects Attendance Tracking Management System | 25/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected by this issue is some unknown functionality of the file /faculty/check_faculty_login.php. The manipulation of the argument faculty_emailid leads to sql injection. The attack may be… | |
| Aplazada | Media (6.4) | 0.35% | — | Data443 Tracking Code ManagerAI | 24/12/2024 | 17/6/2026 | The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (6.9) | 0.60% | — | 1000projects Attendance Tracking Management System | 23/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/course_action.php. The manipulation of the argument course_code leads to sql injection. The attack may be initiated remotely. The exploit… | |
| Analizada | Media (5.3) | 0.54% | — | 1000projects Attendance Tracking Management System | 23/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/faculty_action.php. The manipulation of the argument faculty_course_id leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.68% | — | 1000projects Attendance Tracking Management System | 19/12/2024 | 17/6/2026 | A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/check_student_login.php. The manipulation of the argument student_emailid leads to sql injection. The attack can be… | |
| Modificada | Media (4.8) | 0.30% | — | Sunbirddcim Dctrack | 16/12/2024 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens. | |
| Modificada | Alta (7.5) | 0.47% | — | Sunbirddcim Dctrack | 16/12/2024 | 5/7/2026 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check. | |
| Modificada | Alta (8) | 0.20% | — | Sunbirddcim Dctrack | 16/12/2024 | 5/7/2026 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. | |
| Modificada | Media (4.8) | 0.23% | — | Sunbirddcim Dctrack | 16/12/2024 | 5/7/2026 | An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen. | |
| Aplazada | Media (5.4) | 0.51% | — | Arni Cinco Wpcargo Track TraceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2. |