Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.51%—Arni Cinco Wpcargo Track TraceAI13/12/202417/6/2026
Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.
AnalizadaAlta (8.6)0.36%—Plextrac13/12/202417/6/2026
Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaAlta (8.6)0.44%—Plextrac13/12/202417/6/2026
External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API endpoint.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaAlta (8.6)0.48%—Plextrac13/12/202417/6/2026
Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac allows N1QL Injection.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaAlta (8.6)0.28%—Plextrac13/12/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaAlta (7)0.40%—Plextrac13/12/202417/6/2026
Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaAlta (8.9)0.50%—Plextrac13/12/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaAlta (8.9)0.50%—Plextrac13/12/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
AnalizadaMedia (6.9)0.87%—1000projects Attendance Tracking Management System12/12/202417/6/2026
A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injection. It is possible to launch the attack remotely. The exploit…
AplazadaCrítica (9.8)0.45%—Eryaz Information Technologies Natracar B2B Dealer Management ProgramAI9/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was…
AplazadaMedia (5.3)0.31%—Owasp Dependency-trackAI4/12/202417/6/2026
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username…
AnalizadaMedia (5.3)0.32%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
AnalizadaMedia (6.5)0.60%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
AnalizadaMedia (6.5)0.34%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
AnalizadaMedia (5.3)0.42%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
AnalizadaCrítica (9.8)0.74%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
AnalizadaMedia (6.5)0.36%—Jetbrains Youtrack4/12/202417/6/2026
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
AplazadaAlta (7.5)0.63%—Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI21/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted…
AplazadaAlta (8.5)0.40%—Percent20 Golf TrackerAI9/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in percent20 Golf Tracker golf-tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through <= 0.7.
AplazadaMedia (6.2)0.25%—One2trackAI7/11/202417/6/2026
An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device.
AplazadaMedia (4.6)0.32%—One2trackAI7/11/202417/6/2026
An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by connecting via a USB cable.
AplazadaMedia (6.1)0.40%—CamtraceAI1/11/202417/6/2026
Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php.
AnalizadaAlta (8.8)0.46%—Etoilewebdesign Order Tracking1/11/202417/6/2026
Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.
AplazadaCrítica (9.8)0.65%—Pepegxng Smart ContractAI30/10/202417/6/2026
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls.
AplazadaAlta (8.8)0.49%—Pepegxng Smart ContractAI30/10/202417/6/2026
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _transfer function. NOTE: this is disputed by third parties because the impact is limited to function calls.