Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1387 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Daily Expense Tracker SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | GNU LibextractorAI | 14/9/2026 | 24/9/2026 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and… | |
| Aplazada | Media (6.1) | 0.18% | — | TractAI | 14/9/2026 | 30/9/2026 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor dimensions, the allocation size, and the reported tensor length. Loading a crafted… | |
| Aplazada | Media (6.1) | 0.19% | — | TractAI | 14/9/2026 | 30/9/2026 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tensor.rs get_external_resources and joins the value to the model directory without… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-rbAI | 14/9/2026 | 25/9/2026 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-javaAI | 14/9/2026 | 30/9/2026 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote unauthenticated attacker can send a baggage… | |
| Pendiente de análisis | Crítica (9.9) | 0.86% | 💥 PoC | CpanelAICpanel EmailtrackAI | 9/9/2026 | 10/9/2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | |
| Aplazada | Media (5.5) | 0.27% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin | |
| Aplazada | Media (4.3) | 0.27% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission | |
| Aplazada | Alta (7.7) | 0.30% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission | |
| Aplazada | Media (6.8) | 0.51% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | |
| Aplazada | Media (4.3) | 0.28% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | |
| Aplazada | Media (6.5) | 0.33% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects | |
| Aplazada | Alta (7.7) | 0.30% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | |
| Aplazada | Media (6.5) | 0.30% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards | |
| Aplazada | Alta (8.5) | 0.90% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | |
| Aplazada | Baja (3.5) | 0.24% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | |
| Aplazada | Media (6.5) | 0.33% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | |
| Aplazada | Media (6.5) | 0.34% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | |
| Aplazada | Media (6.5) | 0.34% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | |
| Aplazada | Baja (3.1) | 0.20% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | |
| Aplazada | Baja (3.7) | 0.26% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | |
| Aplazada | Baja (3.3) | 0.16% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | |
| Aplazada | Media (4.6) | 0.64% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | |
| Aplazada | Media (5.4) | 0.64% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible |