Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.23%—Bhaskardhote Back Link Tracker20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in anciwasim Back Link Tracker back-link-tracker allows Blind SQL Injection.This issue affects Back Link Tracker: from n/a through <= 1.0.0.
ModificadaAlta (7.8)0.21%—Lakesidesoftware Systrack Lsiagent18/10/202417/6/2026
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.
ModificadaMedia (6.1)0.28%—Maheshpatel Mitm BUG Tracker18/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mahesh_9696 Mitm Bug Tracker mitm-bug-tracker allows Reflected XSS.This issue affects Mitm Bug Tracker: from n/a through <= 1.0.
AnalizadaMedia (6.1)0.45%—Jetbrains Youtrack17/10/202417/6/2026
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
AnalizadaMedia (5.4)0.38%—Jetbrains Youtrack10/10/202417/6/2026
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
AnalizadaMedia (5.3)0.36%—Jetbrains Youtrack19/9/202417/6/2026
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
AnalizadaMedia (5.3)0.37%—Jetbrains Youtrack19/9/202417/6/2026
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
AnalizadaMedia (4.3)0.33%—Jetbrains Youtrack19/9/202417/6/2026
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
ModificadaCrítica (9.8)0.46%—Wptaskforce Track & Trace17/9/202418/8/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.
AnalizadaMedia (6)0.14%—Dell Precision 7920 Rack FirmwareDell 7920 XL Rack Firmware10/9/202417/6/2026
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+34228/8/202417/6/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
AnalizadaMedia (5.3)0.39%—Rems Task Progress Tracker25/8/202417/6/2026
A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file update-task.php. The manipulation of the argument task_name leads to cross site scripting. The attack may be launched remotely. The exploit has been…
AnalizadaAlta (7.8)0.45%—J4k0xb Webcrack15/8/202417/6/2026
webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module…
AnalizadaMedia (5.3)0.45%—Rems Task Progress Tracker14/8/202417/6/2026
A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-task.php. The manipulation of the argument task_name leads to cross site scripting. The attack can be launched remotely. The…
AnalizadaMedia (5.3)0.57%—Rems Task Progress Tracker14/8/202417/6/2026
A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. The manipulation of the argument task leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
AnalizadaMedia (6.9)0.65%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack…
AnalizadaMedia (5.3)0.55%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_establishment.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has…
AnalizadaMedia (5.3)0.55%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability has been found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_records.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (5.3)0.58%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Tracking Monitoring Management System 1.0. Affected is an unknown function of the file /manage_person.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.55%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management System 1.0. This issue affects some unknown processing of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.54%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Tracking Monitoring Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_establishment. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (6.9)0.37%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.3)0.45%—Oretnom23 Tracking Monitoring Management System1/8/202417/6/2026
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_establishment. The manipulation of the argument name leads to cross site scripting. The attack may be launched…
ModificadaMedia (6.9)0.40%—Oretnom23 Medicine Tracker System30/7/202417/6/2026
A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user of the component Password Change Handler. The manipulation leads to cross-site request forgery. The attack can be initiated…
AplazadaMedia (6.1)0.40%—Getontracks TracksAI26/7/202417/6/2026
Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead…
Orbitaley — Vulnerabilidades