Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1387 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | |
| Analizada | Media (6.1) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | |
| Analizada | Alta (7.1) | 0.21% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | |
| Analizada | Media (5.4) | 0.18% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | |
| Analizada | Media (4.3) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | |
| Analizada | Media (4.3) | 0.65% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | |
| Analizada | Media (4.3) | 0.21% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | |
| Pendiente de análisis | Alta (7.5) | 0.25% | — | Wikimedia UserpageviewtrackerAI | 29/9/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | GNU LibextractorAI | 25/9/2026 | 30/9/2026 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated… | |
| Aplazada | Media (6.9) | 0.41% | — | Openpanel Tracking APIAI | 19/9/2026 | 2/10/2026 | OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters. | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-cppAI | 17/9/2026 | 24/9/2026 | dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even though those limits are enforced during injection. A remote unauthenticated attacker… | |
| Pendiente de análisis | Alta (7.5) | 0.68% | — | Datadog PHP TracerAI | 17/9/2026 | 23/9/2026 | The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES. A remote… | |
| Aplazada | Media (6.5) | 0.53% | — | TraccarAI | 17/9/2026 | 24/9/2026 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. org.traccar.api.resource.GroupResource permits the parent cycle,… | |
| Aplazada | Alta (7.1) | 0.39% | — | TraccarAI | 17/9/2026 | 30/9/2026 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedHashMap<String, Long>) in… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Zenith Satellite TrackerAI | 16/9/2026 | 22/9/2026 | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle ContractsAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle ContractsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle ContractsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | Oracle Contract Lifecycle Management FOR Public SectorAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Daily Expense Tracker SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2) | 0.35% | — | Phpgurukul Daily Expense Tracker SystemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be… |