Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Orlandolac Facilita Form TrackerAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker facilita-form-tracker allows Stored XSS.This issue affects Facilita Form Tracker: from n/a through <= 1.0.
AnalizadaMedia (5.9)0.26%—Data443 Tracking Code Manager30/1/202517/6/2026
The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
AnalizadaAlta (7.8)0.22%—Jetbrains Youtrack21/1/202517/6/2026
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
AnalizadaMedia (5.5)0.60%—Jetbrains Youtrack21/1/202517/6/2026
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
AnalizadaMedia (5.3)0.55%—1000projects Attendance Tracking Management System17/1/202517/6/2026
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The exploit has been…
AplazadaMedia (6.5)0.37%—Alex Furr Progress TrackerAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr Progress Tracker progress-tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through <= 0.9.3.
AplazadaMedia (6.4)0.32%—TrackserverAI11/1/202517/6/2026
The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.32%—Opentracker AnalyticsAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentracker Analytics opentracker-analytics allows Reflected XSS.This issue affects Opentracker Analytics: from n/a through <= 1.3.
AplazadaMedia (4.3)0.41%—Mimo Woocommerce Order TrackingAI9/1/202517/6/2026
The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add, update, and…
AnalizadaMedia (5.3)1.1%—RackDebian Linux9/1/202517/6/2026
There is a denial of service vulnerability in the header parsing component of Rack.
AplazadaMedia (5.5)0.17%—AAT Another Activity TrackerAI6/1/202517/6/2026
AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to data exfiltration from malicious apps installed on the same device.
AnalizadaMedia (5.3)0.45%—1000projects Attendance Tracking Management System30/12/202417/6/2026
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been classified as critical. Affected is the function attendance_report of the file /admin/report.php. The manipulation of the argument course_id leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaMedia (5.3)0.72%—1000projects Attendance Tracking Management System29/12/202417/6/2026
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/attendance_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (6.9)0.61%—1000projects Attendance Tracking Management System26/12/202417/6/2026
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of the file /admin/admin_action.php. The manipulation of the argument admin_user_name leads to sql injection. The attack may be initiated remotely.…
AnalizadaMedia (6.9)0.70%—1000projects Attendance Tracking Management System26/12/202417/6/2026
A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/student_action.php. The manipulation of the argument student_id leads to sql injection. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (6.9)0.60%—1000projects Attendance Tracking Management System25/12/202417/6/2026
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected by this issue is some unknown functionality of the file /faculty/check_faculty_login.php. The manipulation of the argument faculty_emailid leads to sql injection. The attack may be…
AplazadaMedia (6.4)0.35%—Data443 Tracking Code ManagerAI24/12/202417/6/2026
The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaMedia (6.9)0.60%—1000projects Attendance Tracking Management System23/12/202417/6/2026
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/course_action.php. The manipulation of the argument course_code leads to sql injection. The attack may be initiated remotely. The exploit…
AnalizadaMedia (5.3)0.54%—1000projects Attendance Tracking Management System23/12/202417/6/2026
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/faculty_action.php. The manipulation of the argument faculty_course_id leads to sql injection. The attack can be initiated remotely. The…
AnalizadaMedia (6.9)0.68%—1000projects Attendance Tracking Management System19/12/202417/6/2026
A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/check_student_login.php. The manipulation of the argument student_emailid leads to sql injection. The attack can be…
ModificadaMedia (4.8)0.30%—Sunbirddcim Dctrack16/12/20245/7/2026
A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.
ModificadaAlta (7.5)0.47%—Sunbirddcim Dctrack16/12/20245/7/2026
Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.
ModificadaAlta (8)0.20%—Sunbirddcim Dctrack16/12/20245/7/2026
A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
ModificadaMedia (4.8)0.23%—Sunbirddcim Dctrack16/12/20245/7/2026
An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.
AplazadaMedia (5.4)0.51%—Arni Cinco Wpcargo Track TraceAI13/12/202417/6/2026
Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.
Orbitaley — Vulnerabilidades