Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Covid Tracking System | 12/12/2025 | 17/6/2026 | A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=zone. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.39% | — | Angeljudesuarez Covid Tracking System | 12/12/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (3.5) | 0.11% | — | Mediawiki TableprogresstrackingAI | 11/12/2025 | 17/6/2026 | TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would… | |
| Modificada | Media (5.5) | 0.39% | — | Angeljudesuarez Covid Tracking System | 24/11/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 0.31% | — | Angeljudesuarez Covid Tracking System | 23/11/2025 | 17/6/2026 | A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=state. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.31% | — | Angeljudesuarez Covid Tracking System | 23/11/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/?page=city. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.31% | — | Angeljudesuarez Covid Tracking System | 23/11/2025 | 17/6/2026 | A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.31% | — | Angeljudesuarez Covid Tracking System | 23/11/2025 | 30/9/2026 | A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This affects an unknown function of the file /admin/?page=establishment. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Media (6.1) | 0.19% | — | Plausible Tracking Project Plausible Tracking | 30/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS).This issue affects Plausible tracking: from 0.0.0 before 1.0.2. | |
| Aplazada | Baja (2.1) | 0.29% | — | Axosoft Scrum AND BUG TrackingAI | 27/10/2025 | 17/6/2026 | A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing manipulation of the argument Title results in csv injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Cats Information Technology Software Development Technologies Aykome License Tracking SystemAI | 13/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows SQL Injection. This issue affects Aykome License Tracking System: before Version dated 06.10.2025. | |
| Aplazada | Baja (2) | 0.23% | — | Axosoft Scrum AND BUG TrackingAI | 5/10/2025 | 17/6/2026 | A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing of the component Add Work Item Page. The manipulation of the argument Title results in csv injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was… | |
| Aplazada | Media (5.9) | 0.19% | — | Rbaer Simple Matomo Tracking CodeAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0. | |
| Aplazada | Media (5.3) | 0.22% | — | Aftership TrackingAIAftership Woocommerce TrackingAI | 27/8/2025 | 17/6/2026 | Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AfterShip Tracking: from n/a through <= 1.17.17. | |
| Aplazada | Alta (7.2) | 0.41% | — | Adform Site TrackingAI | 19/8/2025 | 17/6/2026 | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1). | |
| Aplazada | Media (5.3) | 0.29% | — | Real-time BUS Tracking SystemAI | 23/7/2025 | 17/6/2026 | Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) condition may be caused by an attacker who can log in to the administrative page of the affected product. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Mavi Yesil Software Guest Tracking SoftwareAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection. This issue affects Guest Tracking Software. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The… | |
| Analizada | Media (4.8) | 0.35% | — | Data443 Tracking Code Manager | 15/5/2025 | 17/6/2026 | The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.3) | 0.36% | — | Mooveagency User Activity Tracking AND LOG | 15/5/2025 | 17/6/2026 | This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. | |
| Modificada | Alta (8.8) | 0.19% | — | Awin - Advertiser Tracking FOR Woocommerce | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-tracking allows Cross Site Request Forgery.This issue affects Awin – Advertiser Tracking for WooCommerce: from n/a through <= 2.0.0. | |
| Modificada | Media (4.8) | 0.28% | — | Apasionados Submission DOM Tracking FOR Contact Form 7 | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Submission DOM tracking for Contact Form 7 cf7-submission-dom-tracking allows Stored XSS.This issue affects Submission DOM tracking for Contact Form 7: from n/a through <= 2.1. | |
| Modificada | Alta (7.2) | 0.48% | — | Wpdever Cart Tracking FOR Woocommerce | 7/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce cart-tracking-for-woocommerce allows SQL Injection.This issue affects Cart tracking for WooCommerce: from n/a through <= 1.0.17. | |
| Aplazada | Alta (7.1) | 0.29% | — | Webparexapp Shipmozo Courier TrackingAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webparexapp Shipmozo Courier Tracking webparex allows Reflected XSS.This issue affects Shipmozo Courier Tracking: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.19% | — | Nimbata Call TrackingAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nimbata Nimbata Call Tracking nimbata-call-tracking allows Stored XSS.This issue affects Nimbata Call Tracking: from n/a through <= 1.7.4. | |
| Aplazada | Media (6.9) | 0.39% | — | Propanetank Roommate Bill TrackingAI | 9/4/2025 | 17/6/2026 | A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated… |