Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.87%—1000projects Attendance Tracking Management System12/12/202417/6/2026
A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injection. It is possible to launch the attack remotely. The exploit…
AnalizadaMedia (6.7)0.17%—Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+110/12/202417/6/2026
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and…
AnalizadaCrítica (9.8)0.76%—Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+110/12/202417/6/2026
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and…
AplazadaMedia (5.3)0.31%—Owasp Dependency-trackAI4/12/202417/6/2026
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username…
AnalizadaMedia (5.3)0.32%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
AnalizadaMedia (6.5)0.60%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
AnalizadaMedia (6.5)0.34%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
AnalizadaMedia (5.3)0.42%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
AnalizadaCrítica (9.8)0.74%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
AnalizadaMedia (6.5)0.36%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
AplazadaAlta (7.5)0.63%—Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI21/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted…
AplazadaAlta (8.5)0.40%—Percent20 Golf TrackerAI9/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in percent20 Golf Tracker golf-tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through <= 0.7.
AplazadaMedia (6.2)0.25%—One2trackAI7/11/202417/6/2026
An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device.
AplazadaMedia (4.6)0.32%—One2trackAI7/11/202417/6/2026
An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by connecting via a USB cable.
AnalizadaAlta (8.8)0.46%—Etoilewebdesign Order Tracking1/11/202417/6/2026
Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.
AplazadaMedia (4.3)0.39%—Bracketspace Advanced Cron ManagerAI1/11/202417/6/2026
Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9.
AnalizadaMedia (5.4)0.32%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
AnalizadaMedia (5.4)0.32%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
AnalizadaMedia (5.4)0.32%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
AnalizadaMedia (6.1)0.32%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
AnalizadaMedia (5.4)0.32%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
AnalizadaMedia (5.4)0.33%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
AnalizadaMedia (5.4)0.32%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
AnalizadaMedia (6.1)0.38%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
AnalizadaAlta (7.5)0.63%—Jetbrains Youtrack28/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
Orbitaley — Vulnerabilidades