Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1068 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.50% | — | Oretnom23 Expense Tracker | 29/9/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected by this issue is some unknown functionality of the file add_category.php of the component Category Handler. The manipulation of the argument category_name leads to cross site scripting. The attack… | |
| Modificada | Media (5.4) | 0.43% | — | Oretnom23 Expense Tracker | 27/9/2023 | 17/6/2026 | Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category. | |
| Modificada | Crítica (9.8) | 1.1% | — | Fit2cloud Rackshift | 14/9/2023 | 17/6/2026 | SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list(). | |
| Modificada | Alta (7.8) | 0.59% | 💥 PoC | Gnome-time Tracker | 14/9/2023 | 17/6/2026 | CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record. | |
| Modificada | Crítica (9.8) | 7.0% | 💥 Exploit | Trendylogics Crypto Currency Tracker | 8/9/2023 | 17/6/2026 | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request. | |
| Modificada | Crítica (9.8) | 0.62% | — | BMA Personnel Tracking System | 5/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904. | |
| Modificada | Baja (2.7) | 0.66% | — | Villatheme Orders Tracking FOR Woocommerce | 4/9/2023 | 17/6/2026 | The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first… | |
| Modificada | Media (4.8) | 0.34% | — | Etoilewebdesign Order Tracking | 31/8/2023 | 17/6/2026 | The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.55% | — | Etoilewebdesign Order Tracking | 31/8/2023 | 17/6/2026 | The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Media (4.3) | 0.25% | — | Mooveagency User Activity Tracking AND LOG | 30/8/2023 | 17/6/2026 | The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks | |
| Modificada | Media (6.1) | 0.48% | — | Cisco Encs 5100 FirmwareCisco Encs 5400 FirmwareCisco UCS C220 M5 Rack Server FirmwareCisco UCS E160s M3 Firmware+2 | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Modificada | Media (6.3) | 0.19% | — | Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+238 | 16/8/2023 | 17/6/2026 | Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system. | |
| Modificada | Crítica (9.8) | 0.63% | — | A2technology Camera Trap Tracking System | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905. | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Alta (7.3) | 0.55% | — | Jetbrains Youtrack | 12/7/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms | |
| Modificada | Media (4.3) | 0.40% | — | Palantir Foundry Job-tracker | 10/7/2023 | 17/6/2026 | A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required. | |
| Modificada | Crítica (9.8) | 0.88% | — | Yontemizleme Vehicle Tracking System | 10/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8. | |
| Modificada | Crítica (9.8) | 1.2% | — | Pdfcrack Project Pdfcrack | 6/7/2023 | 17/6/2026 | An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. |