Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.87% | — | 1000projects Attendance Tracking Management System | 12/12/2024 | 17/6/2026 | A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.7) | 0.17% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Analizada | Crítica (9.8) | 0.76% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Aplazada | Media (5.3) | 0.31% | — | Owasp Dependency-trackAI | 4/12/2024 | 17/6/2026 | Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username… | |
| Analizada | Media (5.3) | 0.32% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | |
| Analizada | Media (6.5) | 0.60% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | |
| Analizada | Media (5.3) | 0.42% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | |
| Analizada | Crítica (9.8) | 0.74% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | |
| Analizada | Media (6.5) | 0.36% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | |
| Aplazada | Alta (7.5) | 0.63% | — | Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI | 21/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted… | |
| Aplazada | Alta (8.5) | 0.40% | — | Percent20 Golf TrackerAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in percent20 Golf Tracker golf-tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through <= 0.7. | |
| Aplazada | Media (6.2) | 0.25% | — | One2trackAI | 7/11/2024 | 17/6/2026 | An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device. | |
| Aplazada | Media (4.6) | 0.32% | — | One2trackAI | 7/11/2024 | 17/6/2026 | An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by connecting via a USB cable. | |
| Analizada | Alta (8.8) | 0.46% | — | Etoilewebdesign Order Tracking | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12. | |
| Aplazada | Media (4.3) | 0.39% | — | Bracketspace Advanced Cron ManagerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9. | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | |
| Analizada | Media (6.1) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | |
| Analizada | Media (5.4) | 0.33% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | |
| Analizada | Media (6.1) | 0.38% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | |
| Analizada | Alta (7.5) | 0.63% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality |