Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.65% | — | Pepegxng Smart ContractAI | 30/10/2024 | 17/6/2026 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls. | |
| Modificada | Media (4.8) | 0.28% | — | Kevonadonis WP Abstracts | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.7.1. | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | |
| Analizada | Media (6.1) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | |
| Analizada | Media (5.4) | 0.33% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | |
| Analizada | Media (6.1) | 0.38% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | |
| Analizada | Alta (7.5) | 0.63% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | |
| Modificada | Alta (8.8) | 0.23% | — | Bhaskardhote Back Link Tracker | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in anciwasim Back Link Tracker back-link-tracker allows Blind SQL Injection.This issue affects Back Link Tracker: from n/a through <= 1.0.0. | |
| Modificada | Alta (7.8) | 0.21% | — | Lakesidesoftware Systrack Lsiagent | 18/10/2024 | 17/6/2026 | Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access. | |
| Modificada | Media (6.1) | 0.28% | — | Maheshpatel Mitm BUG Tracker | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mahesh_9696 Mitm Bug Tracker mitm-bug-tracker allows Reflected XSS.This issue affects Mitm Bug Tracker: from n/a through <= 1.0. | |
| Analizada | Media (6.1) | 0.45% | — | Jetbrains Youtrack | 17/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | |
| Analizada | Alta (8.1) | 0.45% | — | Oracle Service Contracts | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks of… | |
| Analizada | Media (6.9) | 0.55% | — | Codeclysm Extract | 11/10/2024 | 17/6/2026 | Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to… | |
| Analizada | Media (5.4) | 0.38% | — | Jetbrains Youtrack | 10/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API | |
| Modificada | Media (4.8) | 0.31% | — | Kevonadonis WP Abstracts | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.6.5. | |
| Analizada | Media (5.3) | 0.36% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | |
| Analizada | Media (5.3) | 0.37% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | |
| Analizada | Media (4.3) | 0.33% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project | |
| Modificada | Crítica (9.8) | 0.46% | — | Wptaskforce Track & Trace | 17/9/2024 | 18/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4. | |
| Modificada | Media (6.5) | 0.44% | — | Opendaylight Model-driven Service Abstraction Layer | 15/9/2024 | 17/6/2026 | In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment. | |
| Analizada | Media (6.5) | 0.48% | — | Openzeppelin Contracts | 31/8/2024 | 17/6/2026 | Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's intention of leaving the contract without an owner. It introduces a security risk where an unintended party (pending… |