Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.15%—Lenovo Trackpoint Quick MenuAI17/7/202517/6/2026
A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.
AplazadaMedia (6.9)0.37%—Openzeppelin ContractsAI17/7/202517/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to version 5.4.0, the `lastIndexOf(bytes,byte,uint256)` function of the `Bytes.sol` library may access uninitialized memory when the following two conditions hold: 1) the provided buffer length is empty (i.e.…
AnalizadaAlta (7.6)0.29%—Jetbrains Youtrack15/7/202517/6/2026
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
AplazadaCrítica (9.8)0.43%—Mavi Yesil Software Guest Tracking SoftwareAI27/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection. This issue affects Guest Tracking Software. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The…
AplazadaAlta (7.1)0.13%—Ethoseo Track EverythingAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything track-everything allows Stored XSS.This issue affects Track Everything: from n/a through <= 2.0.1.
AplazadaAlta (7.1)0.26%—Track Analyze AND Optimize BY WP TAOAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Track, Analyze & Optimize by WP Tao wp-tao allows Reflected XSS.This issue affects Track, Analyze & Optimize by WP Tao: from n/a through <= 1.3.
AnalizadaAlta (7.3)0.27%—Etracker13/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.
AplazadaAlta (7.6)0.45%—Sinotrack Device Management InterfaceAI12/6/202517/6/2026
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A…
ModificadaMedia (6.5)0.40%—Uptrace Pgdriver12/6/202517/6/2026
uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15.
AnalizadaMedia (6.5)0.44%—Uptrace PG12/6/202517/6/2026
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
AnalizadaMedia (5.3)0.41%—Phpgurukul Daily Expense Tracker System4/6/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /expense-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been…
AplazadaAlta (7)0.16%—PC Time TracerAI3/6/202517/6/2026
Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.
AnalizadaMedia (5.3)0.43%—Phpgurukul Daily Expense Tracker System31/5/202517/6/2026
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /expense-yearwise-reports-detailed.php. The manipulation of the argument todate leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (6.1)0.24%—Bestpractical Request Tracker28/5/202517/6/2026
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
AnalizadaMedia (6.1)0.24%—Bestpractical Request Tracker28/5/202517/6/2026
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
ModificadaMedia (6.1)0.31%—Bestpractical Request Tracker28/5/202517/6/2026
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
AnalizadaAlta (7.5)0.40%—Events LOG Track Project Events LOG Track21/5/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, from 4.0.0 before 4.0.2.
AnalizadaAlta (7.5)0.41%—Jetbrains Youtrack20/5/202517/6/2026
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
AnalizadaMedia (5.3)0.37%—Jetbrains Youtrack20/5/202517/6/2026
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
AnalizadaMedia (6.9)0.51%—Phpgurukul Daily Expense Tracker System19/5/202517/6/2026
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched…
AnalizadaMedia (6.9)0.58%—Phpgurukul Daily Expense Tracker System19/5/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Daily Expense Tracker System 1.1. This affects an unknown part of the file /expense-datewise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (6.9)0.58%—Phpgurukul Daily Expense Tracker System19/5/202517/6/2026
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (6.9)0.73%—Phpgurukul Daily Expense Tracker System16/5/202517/6/2026
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user-profile.php. The manipulation of the argument fullname/contactnumber leads to sql injection. The attack may be launched remotely. The exploit…
AnalizadaMedia (6.9)0.51%—Anujk305 Daily Expense Tracker16/5/202517/6/2026
A vulnerability was found in PHPGurukul Daily Expense Tracker 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaMedia (4.8)0.35%—Data443 Tracking Code Manager15/5/202517/6/2026
The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Orbitaley — Vulnerabilidades