Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Bracketspace Simple Post NotesAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6. | |
| Aplazada | Media (5.9) | 0.36% | — | Bracketspace Advanced Cron ManagerAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2. | |
| Aplazada | Media (4.3) | 0.32% | — | Wedevs Woocommerce Conversion TrackingAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11. | |
| Aplazada | Media (5.9) | 0.32% | — | Data443 Tracking Code ManagerAI | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16. | |
| Modificada | Crítica (9.8) | 0.31% | — | Code-projects Scholars Tracking System | 12/3/2024 | 17/6/2026 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update. | |
| Analizada | Media (5.4) | 0.32% | — | Code-projects Scholars Tracking System | 12/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed. | |
| Analizada | Crítica (9.8) | 0.57% | — | Code-projects Scholars Tracking System | 12/3/2024 | 17/6/2026 | SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information. | |
| Analizada | Alta (7.8) | 0.35% | — | Code-projects Scholars Tracking System | 12/3/2024 | 17/6/2026 | SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php. | |
| Modificada | Media (6.1) | 0.56% | — | Racktables Project Racktables | 12/3/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php. | |
| Analizada | Media (6.5) | 0.52% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | |
| Analizada | Media (6.5) | 0.52% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles | |
| Analizada | Media (5.3) | 0.48% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | |
| Analizada | Alta (7.8) | 0.42% | — | Fabian Scholars Tracking System | 5/3/2024 | 17/6/2026 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed. | |
| Analizada | Media (5.4) | 0.54% | — | Remyandrade Daily Habit Tracker | 1/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/update-tracker.php. The manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (4.9) | 0.49% | — | Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+169 | 1/3/2024 | 17/6/2026 | Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function. | |
| Analizada | Alta (7.5) | 2.0% | — | RackDebian Linux | 29/2/2024 | 17/6/2026 | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2 or newer are… | |
| Analizada | Alta (7.5) | 1.6% | — | RackDebian Linux | 29/2/2024 | 17/6/2026 | Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges`… | |
| Analizada | Alta (7.5) | 35% | — | RackDebian Linux | 29/2/2024 | 17/6/2026 | Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1. | |
| Analizada | Media (5.4) | 0.37% | — | Code-projects Scholars Tracking System | 27/2/2024 | 17/6/2026 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update. | |
| Analizada | Crítica (9.1) | 0.77% | — | Rylabs Rack Cors Middleware | 26/2/2024 | 17/6/2026 | rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files. | |
| Modificada | Crítica (9.8) | 0.81% | — | Rems Simple Expense Tracker APP | 14/2/2024 | 17/6/2026 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php. | |
| Modificada | Crítica (9.8) | 0.81% | — | Rems Simple Expense Tracker APP | 14/2/2024 | 17/6/2026 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php. | |
| Modificada | Alta (8.8) | 0.65% | — | Simgesel Hearing Tracking System | 9/2/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse. This issue affects Hearing Tracking System: before for IOS 7.0, for Android Latest release 1.0. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Remyandrade Daily Habit Tracker | 8/2/2024 | 17/6/2026 | An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components. | |
| Modificada | Crítica (9.8) | 1.3% | 💥 Exploit | Remyandrade Daily Habit Tracker | 8/2/2024 | 17/6/2026 | SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request. |