Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.36% | — | Mooveagency User Activity Tracking AND LOG | 15/5/2025 | 17/6/2026 | This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. | |
| Modificada | Alta (8.8) | 0.19% | — | Awin - Advertiser Tracking FOR Woocommerce | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-tracking allows Cross Site Request Forgery.This issue affects Awin – Advertiser Tracking for WooCommerce: from n/a through <= 2.0.0. | |
| Modificada | Media (4.8) | 0.28% | — | Apasionados Submission DOM Tracking FOR Contact Form 7 | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Submission DOM tracking for Contact Form 7 cf7-submission-dom-tracking allows Stored XSS.This issue affects Submission DOM tracking for Contact Form 7: from n/a through <= 2.1. | |
| Modificada | Alta (7.2) | 0.48% | — | Wpdever Cart Tracking FOR Woocommerce | 7/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce cart-tracking-for-woocommerce allows SQL Injection.This issue affects Cart tracking for WooCommerce: from n/a through <= 1.0.17. | |
| Aplazada | Alta (7.6) | 0.43% | — | Trackship FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TrackShip TrackShip for WooCommerce trackship-for-woocommerce allows SQL Injection.This issue affects TrackShip for WooCommerce: from n/a through <= 1.9.1. | |
| Aplazada | Baja (2.3) | 0.19% | — | Best Practical Solutions LLC Request TrackerAI | 5/5/2025 | 17/6/2026 | Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Coresmartcontracts UniswapAI | 29/4/2025 | 17/6/2026 | An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function | |
| Aplazada | Media (4.8) | 0.23% | — | Sarrionandia TournatrackAIPalletsprojects JinjaAI | 19/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py of the component Jinja2 Template Handler. The manipulation of the argument ID leads to injection. It is… | |
| Aplazada | Alta (7.1) | 0.29% | — | Wecantrack Affiliate Links LiteAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wecantrack Affiliate Links Lite affiliate-links allows Reflected XSS.This issue affects Affiliate Links Lite: from n/a through <= 3.1.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | 17track FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 17track 17TRACK for WooCommerce 17track allows Reflected XSS.This issue affects 17TRACK for WooCommerce: from n/a through <= 1.2.10. | |
| Aplazada | Alta (7.1) | 0.29% | — | Webparexapp Shipmozo Courier TrackingAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webparexapp Shipmozo Courier Tracking webparex allows Reflected XSS.This issue affects Shipmozo Courier Tracking: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Bitsstech Shipment Tracker FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bitsstech Shipment Tracker for Woocommerce shipment-tracker-for-woocommerce allows Reflected XSS.This issue affects Shipment Tracker for Woocommerce: from n/a through <= 1.4.23. | |
| Aplazada | Crítica (9.3) | 0.65% | — | Lisandro Martinez Wp-smart-contractsAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: from n/a through <= 2.0.12. | |
| Aplazada | Alta (7.5) | 0.56% | — | Anytrack Affiliate Link ManagerAI | 11/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyTrack Affiliate Link Manager: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.19% | — | Nimbata Call TrackingAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nimbata Nimbata Call Tracking nimbata-call-tracking allows Stored XSS.This issue affects Nimbata Call Tracking: from n/a through <= 1.7.4. | |
| Aplazada | Alta (7.1) | 0.19% | — | Kevonadonis WP AbstractsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Cross Site Request Forgery.This issue affects WP Abstracts: from n/a through <= 2.7.5. | |
| Aplazada | Media (4.7) | 0.10% | — | Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI | 9/4/2025 | 17/6/2026 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.… | |
| Aplazada | Media (6.9) | 0.39% | — | Propanetank Roommate Bill TrackingAI | 9/4/2025 | 17/6/2026 | A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Shiptrack Booking Calendar AND NotificationAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification booking-calendar-and-notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through <= 4.0.3. | |
| Aplazada | Media (6.5) | 0.33% | — | Shiptrack Booking Calendar AND NotificationAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in shiptrack Booking Calendar and Notification booking-calendar-and-notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar and Notification: from n/a through <= 4.0.3. | |
| Aplazada | Media (4.3) | 0.25% | — | Arni Cinco Wpcargo Track AND TraceAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Tinuzz TrackserverAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tinuzz Trackserver trackserver allows DOM-Based XSS.This issue affects Trackserver: from n/a through <= 5.1.0. | |
| Aplazada | Alta (8.3) | 0.32% | — | Nightwolf Penetration Testing TrackingAI | 31/3/2025 | 17/6/2026 | Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Piextract Soop-clmAI | 31/3/2025 | 17/6/2026 | SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (5.4) | 0.15% | — | Misteraon Simple Trackback DisablerAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in misteraon Simple Trackback Disabler simple-trackback-disabler allows Cross Site Request Forgery.This issue affects Simple Trackback Disabler: from n/a through <= 1.4. |