Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)26%💥 ExploitRemyandrade Daily Habit Tracker8/2/202417/6/2026
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.
ModificadaMedia (6.1)0.33%—Webdados Portugal CTT Tracking FOR Woocommerce8/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | Webdados Portugal CTT Tracking for WooCommerce portugal-ctt-tracking-woocommerce.This issue affects Portugal CTT Tracking for WooCommerce: from n/a through <= 2.1.
ModificadaAlta (7.2)1.2%💥 PoCRemyandrade Daily Habit Tracker29/1/202417/6/2026
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
ModificadaAlta (8.8)1.1%—Tracktheclick Track THE Click17/1/202417/6/2026
The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.
ModificadaAlta (7.2)0.63%—Oretnom23 Budget AND Expense Tracker System16/1/202417/6/2026
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=
ModificadaMedia (5.4)0.41%—Jetbrains Youtrack9/1/202417/6/2026
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
ModificadaCrítica (9.8)0.94%—Oretnom23 Medicine Tracker System28/12/202317/6/2026
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaCrítica (9.8)0.68%—Oretnom23 Medicine Tracker System28/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracking System 1.0. This issue affects some unknown processing of the file /classes/Master.php? f=save_medicine. The manipulation of the argument id/name/description leads to sql injection. The attack may be initiated…
ModificadaAlta (7.5)0.83%—Typelevel Grackle22/12/202317/6/2026
Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must not form cycles, either directly or indirectly. Prior to Grackle version 0.18.0, that requirement wasn't checked, and queries with cyclic fragments would have been…
ModificadaCrítica (9.8)1.8%—Uffizio GPS Tracker16/12/202317/6/2026
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resources
ModificadaMedia (6.1)0.49%—Uffizio GPS Tracker16/12/202317/6/2026
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
ModificadaAlta (7.5)0.84%—Uffizio GPS Tracker16/12/202317/6/2026
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.
ModificadaMedia (4.8)0.39%—Zealousweb Track Geolocation OF Users Using Contact Form 715/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 2.0.
ModificadaMedia (4.3)0.45%—Jetbrains Youtrack15/12/202317/6/2026
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
ModificadaMedia (5.4)0.39%—Labs64 Credit Tracker14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labs64 Credit Tracker allows Stored XSS.This issue affects Credit Tracker: from n/a through 1.1.17.
ModificadaCrítica (9.8)0.71%—Veom Service Tracking22/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Service Tracking Software allows SQL Injection. This issue affects Service Tracking Software: before crm 2.0.
ModificadaAlta (7.5)0.60%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
ModificadaAlta (7.5)0.70%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
ModificadaAlta (7.5)0.72%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
ModificadaAlta (7.5)0.47%—Smartmodules Facebookconversiontrackingplus2/11/202317/6/2026
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can…
ModificadaMedia (5.4)0.44%—Callrail Phone Call Tracking27/10/202317/6/2026
The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_form' shortcode in versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on the 'form_id' user supplied attribute. This makes it possible for authenticated…
ModificadaAlta (8.2)0.58%—Linecorp Trackdiner10/10 MC25/10/202317/6/2026
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
ModificadaMedia (6.1)0.51%—Oretnom23 Medicine Tracker System14/10/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.7)0.86%—Gnome Tracker MinersRedhat Enterprise Linux13/10/202317/6/2026
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
ModificadaMedia (5.4)0.50%—Oretnom23 Expense Tracker29/9/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected by this issue is some unknown functionality of the file add_category.php of the component Category Handler. The manipulation of the argument category_name leads to cross site scripting. The attack…
Orbitaley — Vulnerabilidades