Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.63% | — | A2technology Camera Trap Tracking System | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905. | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Media (5.4) | 1.1% | — | Jaegertracing Jaeger UI | 17/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component. | |
| Modificada | Alta (7.3) | 0.55% | — | Jetbrains Youtrack | 12/7/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms | |
| Analizada | Alta (8.8) | 0.26% | — | Kevonadonis WP Abstracts | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |
| Modificada | Media (4.3) | 0.40% | — | Palantir Foundry Job-tracker | 10/7/2023 | 17/6/2026 | A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required. | |
| Modificada | Crítica (9.8) | 0.88% | — | Yontemizleme Vehicle Tracking System | 10/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8. | |
| Modificada | Media (6.1) | 0.27% | — | Darktrace Threat Visualizer | 6/7/2023 | 17/6/2026 | An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability could create a "shutdown", blocking all ingress or egress traffic in the entire… | |
| Modificada | Media (5.9) | 0.37% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 16/6/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions are in use, it is possible to construct merkle trees that allow forging a… | |
| Modificada | Media (5.4) | 0.97% | — | Jetbrains Youtrack | 12/6/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible | |
| Modificada | Alta (7.5) | 0.62% | — | Jetbrains Youtrack | 12/6/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | |
| Analizada | Media (6.1) | 0.38% | — | Kevonadonis WP Abstracts | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | UTM Tracker Project UTM Tracker | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ludwig Media UTM Tracker plugin <= 1.3.1 versions. | |
| Modificada | Media (4.8) | 2.3% | 💥 Exploit | Sales Tracker Management System Project Sales Tracker Management System | 9/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The… | |
| Modificada | Media (5.3) | 0.60% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 7/6/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in… | |
| Modificada | Media (6.5) | 0.65% | — | Zorem Advanced Shipment Tracking FOR Woocommerce | 7/6/2023 | 17/6/2026 | The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5… | |
| Modificada | Alta (8.8) | 0.26% | — | Zorem Advanced Shipment Tracking FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions. | |
| Modificada | Crítica (9.8) | 0.62% | — | Minovateknoloji Etrace | 24/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20. | |
| Modificada | Crítica (9.8) | 0.62% | — | Ipekyolunet Software Auto Damage Tracking Software | 24/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4. | |
| Modificada | Alta (8.8) | 0.85% | — | Armoli Cargo Tracking System | 24/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass. This issue affects Cargo Tracking System: before 3558f28 . | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Budget AND Expense Tracker System | 17/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Budget and Expense Tracker System 1.0. Affected is an unknown function of the file /admin/budget/manage_budget.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch… | |
| Modificada | Media (6.1) | 0.66% | — | Algoo Tracim | 17/5/2023 | 17/6/2026 | Algoo Tracim before 4.4.2 allows XSS via HTML file upload. | |
| Modificada | Crítica (9.8) | 0.66% | — | Anuko Time Tracker | 15/5/2023 | 17/6/2026 | anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. This was happening because of a coding error after validating parameters in POST requests. There was no check for errors before adjusting… | |
| Modificada | Crítica (9.8) | 0.72% | — | Anuko Time Tracker | 12/5/2023 | 17/6/2026 | Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker reports in versions prior to 1.22.13.5792. This was happening because the `reports.php` page was not validating all parameters in POST requests. Because some parameters were not checked, it was… | |
| Modificada | Alta (7.8) | 0.16% | — | Intel Trace Analyzer AND Collector | 12/5/2023 | 17/6/2026 | Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially enable escalation of privilege via local access. |