Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.20%—Bracketspace Simple Post NotesAI11/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6.
AplazadaMedia (5.9)0.36%—Bracketspace Advanced Cron ManagerAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2.
AplazadaMedia (4.3)0.32%—Wedevs Woocommerce Conversion TrackingAI26/3/202417/6/2026
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.
AplazadaMedia (5.9)0.32%—Data443 Tracking Code ManagerAI21/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.
ModificadaCrítica (9.8)0.31%—Code-projects Scholars Tracking System12/3/202417/6/2026
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
AnalizadaMedia (5.4)0.32%—Code-projects Scholars Tracking System12/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.
AnalizadaCrítica (9.8)0.57%—Code-projects Scholars Tracking System12/3/202417/6/2026
SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.
AnalizadaAlta (7.8)0.35%—Code-projects Scholars Tracking System12/3/202417/6/2026
SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.
ModificadaMedia (6.1)0.56%—Racktables Project Racktables12/3/202417/6/2026
Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.
AnalizadaMedia (6.5)0.52%—Jetbrains Youtrack7/3/202417/6/2026
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
AnalizadaMedia (6.5)0.52%—Jetbrains Youtrack7/3/202417/6/2026
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
AnalizadaMedia (5.3)0.48%—Jetbrains Youtrack7/3/202417/6/2026
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
AnalizadaAlta (7.8)0.42%—Fabian Scholars Tracking System5/3/202417/6/2026
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
AnalizadaMedia (5.4)0.54%—Remyandrade Daily Habit Tracker1/3/202417/6/2026
A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/update-tracker.php. The manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The…
AnalizadaMedia (4.9)0.49%—Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+1691/3/202417/6/2026
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
AnalizadaAlta (7.5)2.0%—RackDebian Linux29/2/202417/6/2026
Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are…
AnalizadaAlta (7.5)1.6%—RackDebian Linux29/2/202417/6/2026
Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges`…
AnalizadaAlta (7.5)35%—RackDebian Linux29/2/202417/6/2026
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
AnalizadaMedia (5.4)0.37%—Code-projects Scholars Tracking System27/2/202417/6/2026
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
AnalizadaCrítica (9.1)0.77%—Rylabs Rack Cors Middleware26/2/202417/6/2026
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
ModificadaCrítica (9.8)0.81%—Rems Simple Expense Tracker APP14/2/202417/6/2026
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.
ModificadaCrítica (9.8)0.81%—Rems Simple Expense Tracker APP14/2/202417/6/2026
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.
ModificadaAlta (8.8)0.65%—Simgesel Hearing Tracking System9/2/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse. This issue affects Hearing Tracking System: before for IOS 7.0, for Android Latest release 1.0.
ModificadaCrítica (9.8)20%💥 ExploitRemyandrade Daily Habit Tracker8/2/202417/6/2026
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
ModificadaCrítica (9.8)1.3%💥 ExploitRemyandrade Daily Habit Tracker8/2/202417/6/2026
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.
Orbitaley — Vulnerabilidades