Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.17% | — | Dell Edge Gateway 3200 FirmwareDell Edge Gateway 5200 FirmwareDell Precision 3930 Rack FirmwareDell Optiplex 7080 Firmware+6 | 24/7/2024 | 17/6/2026 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits. | |
| Aplazada | Media (5.9) | 0.27% | — | Bracketspace Simple Post NotesAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BracketSpace Simple Post Notes allows Stored XSS.This issue affects Simple Post Notes: from n/a through 1.7.7. | |
| Modificada | Media (5.4) | 0.33% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. | |
| Modificada | Media (5.4) | 0.29% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header. | |
| Modificada | Media (5.4) | 0.29% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS. | |
| Analizada | Media (6.5) | 0.86% | — | Rack | 2/7/2024 | 17/6/2026 | Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists in the `Rack::Request::Helpers` module when parsing HTTP Accept headers. This vulnerability can be exploited by an attacker sending specially crafted… | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Modificada | Media (5.3) | 0.57% | — | Oretnom23 Medicine Tracker System | 1/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.9) | 0.51% | — | Oretnom23 Medicine Tracker System | 30/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 2.0% | 💥 Exploit | Parsec Automation TracksysAI | 20/6/2024 | 17/6/2026 | A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (6.4) | 0.24% | — | Mimo Woocommerce Order TrackingAI | 19/6/2024 | 17/6/2026 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mimo_update_provider' function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Alta (8.1) | 0.31% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | |
| Modificada | Alta (7.5) | 0.44% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | |
| Modificada | Media (5.3) | 0.36% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | |
| Modificada | Media (6.3) | 0.23% | — | Wedevs Woocommerce Conversion Tracking | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11. | |
| Aplazada | Media (4.3) | 0.28% | — | Data443 Tracking Code ManagerAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0. | |
| Modificada | Media (6.1) | 0.29% | — | Loopus WP Visitors Tracker | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3. | |
| Aplazada | Alta (8.6) | 0.67% | — | Rack-contribAI | 27/5/2024 | 17/6/2026 | rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of service due to the fact that the user controlled data `profiler_runs` was not constrained to any limitation. This would lead to allocating resources… | |
| Analizada | Alta (7.5) | 0.27% | — | Jetbrains Youtrack | 16/5/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | |
| Aplazada | Media (6.5) | 0.62% | — | Villatheme Orders Tracking FOR WoocommerceAI | 14/5/2024 | 17/6/2026 | The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Aplazada | Alta (7.1) | 0.44% | — | Wp-etracker WP EtrackerAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2. | |
| Analizada | Alta (8.8) | 1.7% | — | BMC Track-it! | 7/5/2024 | 17/6/2026 | BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of email attachments. The… | |
| Analizada | Media (6.5) | 0.76% | — | BMC Track-it! | 7/5/2024 | 17/6/2026 | BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The… | |
| Aplazada | Media (5.3) | 0.38% | — | Trackship FOR WoocommerceAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in TrackShip TrackShip for WooCommerce.This issue affects TrackShip for WooCommerce: from n/a through 1.7.5. | |
| Modificada | Media (6.1) | 0.35% | — | Wpgoaltracker WP Google Analytics Events | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google Analytics Events allows Reflected XSS.This issue affects WP Google Analytics Events: from n/a through 2.8.0. |