Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.45%—Forip Administracao PabxAI25/7/202417/6/2026
A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The…
AplazadaAlta (7.8)0.31%—NI I O Trace ToolAINI System ConfigurationAINI SPYAI23/7/202417/6/2026
A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted nitrace file. The NI I/O Trace tool is installed as part of the NI System Configuration…
ModificadaMedia (5.4)0.33%—Roundup-tracker Roundup17/7/202417/6/2026
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
ModificadaMedia (5.4)0.29%—Roundup-tracker Roundup17/7/202417/6/2026
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
ModificadaMedia (5.4)0.29%—Roundup-tracker Roundup17/7/202417/6/2026
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
ModificadaMedia (5.3)0.57%—Oretnom23 Medicine Tracker System1/7/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaMedia (6.9)0.51%—Oretnom23 Medicine Tracker System30/6/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AplazadaAlta (7.5)0.43%—Datadog Dd-trace-cppAINlohmann JsonAI28/6/202417/6/2026
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results…
AplazadaMedia (6.9)2.0%💥 ExploitParsec Automation TracksysAI20/6/202417/6/2026
A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public…
AplazadaMedia (6.4)0.24%—Mimo Woocommerce Order TrackingAI19/6/202417/6/2026
The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mimo_update_provider' function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
ModificadaAlta (8.1)0.31%—Jetbrains Youtrack18/6/202417/6/2026
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
ModificadaAlta (7.5)0.44%—Jetbrains Youtrack18/6/202417/6/2026
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
ModificadaMedia (5.3)0.36%—Jetbrains Youtrack18/6/202417/6/2026
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
ModificadaMedia (6.3)0.23%—Wedevs Woocommerce Conversion Tracking11/6/202417/6/2026
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.
AplazadaMedia (4.3)0.28%—Data443 Tracking Code ManagerAI9/6/202417/6/2026
Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0.
ModificadaMedia (6.1)0.29%—Loopus WP Visitors Tracker8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3.
ModificadaAlta (7.5)0.81%—Redhat Openshift Container PlatformRedhat Openshift Distributed Tracing5/6/202417/6/2026
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
AplazadaBaja (2.8)0.20%—Intel Trace Analyzer AND CollectorAI16/5/202417/6/2026
Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access.
AnalizadaAlta (7.5)0.27%—Jetbrains Youtrack16/5/202417/6/2026
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
AplazadaMedia (6.5)0.62%—Villatheme Orders Tracking FOR WoocommerceAI14/5/202417/6/2026
The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…
AplazadaAlta (7.1)0.44%—Wp-etracker WP EtrackerAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.
AnalizadaAlta (8.8)1.7%—BMC Track-it!7/5/202417/6/2026
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of email attachments. The…
AnalizadaMedia (6.5)0.76%—BMC Track-it!7/5/202417/6/2026
BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The…
AplazadaMedia (5.3)0.38%—Trackship FOR WoocommerceAI24/4/202417/6/2026
Missing Authorization vulnerability in TrackShip TrackShip for WooCommerce.This issue affects TrackShip for WooCommerce: from n/a through 1.7.5.
AplazadaAlta (7.3)0.78%—Nokia C200AINokia C100AITracfone TfstatusAI22/4/202417/6/2026
Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection…