Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.59% | — | File Tracker Manager System Project File Tracker Manager System | 12/5/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester File Tracker Manager System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /file_manager/admin/save_user.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The… | |
| Modificada | Alta (8.8) | 0.78% | — | Covid-19 Contact Tracing System Project Covid-19 Contact Tracing System | 12/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Covid-19 Contact Tracing System 1.0. This affects an unknown part of the file admin/establishment/manage.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.73% | — | File Tracker Manager System Project File Tracker Manager System | 11/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester File Tracker Manager System 1.0. This vulnerability affects unknown code of the file register/update_password.php of the component POST Parameter Handler. The manipulation of the argument new_password leads to sql injection. The attack can be initiated… | |
| Modificada | Alta (8.8) | 0.65% | — | Intel Wake UP Latency Tracer | 10/5/2023 | 17/6/2026 | Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Stack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Stack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.4) | 0.37% | — | Anuko Time Tracker | 9/5/2023 | 17/6/2026 | Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such script could then be executed in user… | |
| Modificada | Alta (7.5) | 0.62% | — | Medicine Tracker System Project Medicine Tracker System | 26/4/2023 | 17/6/2026 | Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection. | |
| Modificada | Media (6.1) | 0.39% | — | Medicine Tracker System Project Medicine Tracker System | 26/4/2023 | 17/6/2026 | Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.51% | — | Medicine Tracker System Project Medicine Tracker System | 26/4/2023 | 17/6/2026 | Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about. | |
| Modificada | Media (5.3) | 0.84% | 💥 PoC | Medicine Tracker System Project Medicine Tracker System | 24/4/2023 | 17/6/2026 | A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password. | |
| Modificada | Media (4.8) | 0.39% | — | WP Clictracker Project WP Clictracker | 18/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions. | |
| Modificada | Media (5.3) | 0.81% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 17/4/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if the clashing function has a different signature with incompatible ABI encoding, the proxy could revert… | |
| Modificada | Media (5.4) | 0.44% | — | Timesheets-for-jira Timesheet Tracking | 17/4/2023 | 17/6/2026 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. | |
| Modificada | Alta (8.8) | 0.58% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 16/4/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter than the `calldatas` array. This causes the additional elements of the latter to be ignored, and if… | |
| Modificada | Crítica (9.8) | 0.74% | — | Sales Tracker Management System Project Sales Tracker Management System | 11/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The… | |
| Modificada | Media (6.1) | 0.88% | — | Sales Tracker Management System Project Sales Tracker Management System | 10/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file. | |
| Modificada | Alta (7.5) | 1.4% | — | Sales Tracker Management System Project Sales Tracker Management System | 10/4/2023 | 17/6/2026 | An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint. | |
| Modificada | Alta (7.5) | 0.58% | — | Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP | 5/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997… | |
| Modificada | Crítica (9.8) | 0.89% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 5/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file admin/. The manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.74% | — | Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP | 31/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this… |