Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.51% | — | Arni Cinco Wpcargo Track TraceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2. | |
| Analizada | Alta (8.6) | 0.36% | — | Plextrac | 13/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Alta (8.6) | 0.44% | — | Plextrac | 13/12/2024 | 17/6/2026 | External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API endpoint.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Alta (8.6) | 0.48% | — | Plextrac | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac allows N1QL Injection.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Alta (8.6) | 0.28% | — | Plextrac | 13/12/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Alta (7) | 0.40% | — | Plextrac | 13/12/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Alta (8.9) | 0.50% | — | Plextrac | 13/12/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Alta (8.9) | 0.50% | — | Plextrac | 13/12/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Analizada | Media (6.9) | 0.87% | — | 1000projects Attendance Tracking Management System | 12/12/2024 | 17/6/2026 | A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Eryaz Information Technologies Natracar B2B Dealer Management ProgramAI | 9/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was… | |
| Aplazada | Media (5.3) | 0.31% | — | Owasp Dependency-trackAI | 4/12/2024 | 17/6/2026 | Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username… | |
| Analizada | Media (5.3) | 0.32% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | |
| Analizada | Media (6.5) | 0.60% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | |
| Analizada | Media (5.3) | 0.42% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | |
| Analizada | Crítica (9.8) | 0.74% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | |
| Analizada | Media (6.5) | 0.36% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | |
| Aplazada | Alta (7.5) | 0.63% | — | Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI | 21/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted… | |
| Aplazada | Alta (8.5) | 0.40% | — | Percent20 Golf TrackerAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in percent20 Golf Tracker golf-tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through <= 0.7. | |
| Aplazada | Media (6.2) | 0.25% | — | One2trackAI | 7/11/2024 | 17/6/2026 | An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device. | |
| Aplazada | Media (4.6) | 0.32% | — | One2trackAI | 7/11/2024 | 17/6/2026 | An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by connecting via a USB cable. | |
| Aplazada | Media (6.1) | 0.40% | — | CamtraceAI | 1/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php. | |
| Analizada | Alta (8.8) | 0.46% | — | Etoilewebdesign Order Tracking | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Pepegxng Smart ContractAI | 30/10/2024 | 17/6/2026 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls. | |
| Aplazada | Alta (8.8) | 0.49% | — | Pepegxng Smart ContractAI | 30/10/2024 | 17/6/2026 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _transfer function. NOTE: this is disputed by third parties because the impact is limited to function calls. |