Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.45% | — | Forip Administracao PabxAI | 25/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Alta (7.8) | 0.31% | — | NI I O Trace ToolAINI System ConfigurationAINI SPYAI | 23/7/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted nitrace file. The NI I/O Trace tool is installed as part of the NI System Configuration… | |
| Modificada | Media (5.4) | 0.33% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. | |
| Modificada | Media (5.4) | 0.29% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header. | |
| Modificada | Media (5.4) | 0.29% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS. | |
| Modificada | Media (5.3) | 0.57% | — | Oretnom23 Medicine Tracker System | 1/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.9) | 0.51% | — | Oretnom23 Medicine Tracker System | 30/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Alta (7.5) | 0.43% | — | Datadog Dd-trace-cppAINlohmann JsonAI | 28/6/2024 | 17/6/2026 | dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results… | |
| Aplazada | Media (6.9) | 2.0% | 💥 Exploit | Parsec Automation TracksysAI | 20/6/2024 | 17/6/2026 | A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (6.4) | 0.24% | — | Mimo Woocommerce Order TrackingAI | 19/6/2024 | 17/6/2026 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mimo_update_provider' function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Alta (8.1) | 0.31% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | |
| Modificada | Alta (7.5) | 0.44% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | |
| Modificada | Media (5.3) | 0.36% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | |
| Modificada | Media (6.3) | 0.23% | — | Wedevs Woocommerce Conversion Tracking | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11. | |
| Aplazada | Media (4.3) | 0.28% | — | Data443 Tracking Code ManagerAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0. | |
| Modificada | Media (6.1) | 0.29% | — | Loopus WP Visitors Tracker | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3. | |
| Modificada | Alta (7.5) | 0.81% | — | Redhat Openshift Container PlatformRedhat Openshift Distributed Tracing | 5/6/2024 | 17/6/2026 | A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication. | |
| Aplazada | Baja (2.8) | 0.20% | — | Intel Trace Analyzer AND CollectorAI | 16/5/2024 | 17/6/2026 | Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Analizada | Alta (7.5) | 0.27% | — | Jetbrains Youtrack | 16/5/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | |
| Aplazada | Media (6.5) | 0.62% | — | Villatheme Orders Tracking FOR WoocommerceAI | 14/5/2024 | 17/6/2026 | The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Aplazada | Alta (7.1) | 0.44% | — | Wp-etracker WP EtrackerAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2. | |
| Analizada | Alta (8.8) | 1.7% | — | BMC Track-it! | 7/5/2024 | 17/6/2026 | BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of email attachments. The… | |
| Analizada | Media (6.5) | 0.76% | — | BMC Track-it! | 7/5/2024 | 17/6/2026 | BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The… | |
| Aplazada | Media (5.3) | 0.38% | — | Trackship FOR WoocommerceAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in TrackShip TrackShip for WooCommerce.This issue affects TrackShip for WooCommerce: from n/a through 1.7.5. | |
| Aplazada | Alta (7.3) | 0.78% | — | Nokia C200AINokia C100AITracfone TfstatusAI | 22/4/2024 | 17/6/2026 | Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection… |