Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1068 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.26%—Zorem Advanced Shipment Tracking FOR Woocommerce25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions.
ModificadaCrítica (9.8)0.62%—Ipekyolunet Software Auto Damage Tracking Software24/5/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4.
ModificadaAlta (8.8)0.85%—Armoli Cargo Tracking System24/5/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass. This issue affects Cargo Tracking System: before 3558f28 .
ModificadaAlta (8.8)0.73%—Oretnom23 Budget AND Expense Tracker System17/5/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Budget and Expense Tracker System 1.0. Affected is an unknown function of the file /admin/budget/manage_budget.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch…
ModificadaCrítica (9.8)0.66%—Anuko Time Tracker15/5/202317/6/2026
anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. This was happening because of a coding error after validating parameters in POST requests. There was no check for errors before adjusting…
ModificadaCrítica (9.8)0.72%—Anuko Time Tracker12/5/202317/6/2026
Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker reports in versions prior to 1.22.13.5792. This was happening because the `reports.php` page was not validating all parameters in POST requests. Because some parameters were not checked, it was…
ModificadaMedia (5.4)0.59%—File Tracker Manager System Project File Tracker Manager System12/5/202317/6/2026
A vulnerability has been found in SourceCodester File Tracker Manager System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /file_manager/admin/save_user.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The…
ModificadaCrítica (9.8)0.73%—File Tracker Manager System Project File Tracker Manager System11/5/202317/6/2026
A vulnerability classified as critical was found in SourceCodester File Tracker Manager System 1.0. This vulnerability affects unknown code of the file register/update_password.php of the component POST Parameter Handler. The manipulation of the argument new_password leads to sql injection. The attack can be initiated…
ModificadaMedia (5.4)0.37%—Anuko Time Tracker9/5/202317/6/2026
Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such script could then be executed in user…
ModificadaAlta (7.5)0.62%—Medicine Tracker System Project Medicine Tracker System26/4/202317/6/2026
Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.
ModificadaMedia (6.1)0.39%—Medicine Tracker System Project Medicine Tracker System26/4/202317/6/2026
Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (6.1)0.51%—Medicine Tracker System Project Medicine Tracker System26/4/202317/6/2026
Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.
ModificadaMedia (5.3)0.84%💥 PoCMedicine Tracker System Project Medicine Tracker System24/4/202317/6/2026
A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.
ModificadaMedia (4.8)0.39%—WP Clictracker Project WP Clictracker18/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
ModificadaMedia (5.4)0.44%—Timesheets-for-jira Timesheet Tracking17/4/202317/6/2026
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
ModificadaCrítica (9.8)0.74%—Sales Tracker Management System Project Sales Tracker Management System11/4/202317/6/2026
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The…
ModificadaMedia (6.1)0.88%—Sales Tracker Management System Project Sales Tracker Management System10/4/202317/6/2026
Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file.
ModificadaAlta (7.5)1.4%—Sales Tracker Management System Project Sales Tracker Management System10/4/202317/6/2026
An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.
ModificadaAlta (7.5)0.58%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP5/4/202317/6/2026
A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997…
ModificadaCrítica (9.8)0.74%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP31/3/202317/6/2026
A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this…
ModificadaMedia (6.1)0.36%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP29/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated…
ModificadaMedia (6.1)0.36%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP29/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnerability affects unknown code of the file Master.php?a=save_earning. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The identifier of this…
ModificadaMedia (6.1)0.36%—Oretnom23 Earnings AND Expense Tracker Application29/3/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated…
ModificadaMedia (5.4)0.89%💥 ExploitTechnocrackers Bulk Price Update FOR Woocommerce22/3/202317/6/2026
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
ModificadaCrítica (9.8)0.79%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/username/password leads to improper authentication. It is possible to initiate the…