Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1064 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.46%—Wpcargo Track AND TraceAI6/8/202626/8/2026
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
AplazadaBaja (2.1)0.23%—RacktablesAI4/8/202612/8/2026
A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The…
AplazadaAlta (7.1)0.19%—Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+2530/7/202618/9/2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,…
AplazadaCrítica (9.1)0.41%—Project Management BUG AND Issue Tracking PluginAI24/7/202624/7/2026
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin…
AplazadaMedia (5.3)0.37%—Froiden TabletrackAI22/7/20267/8/2026
Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser…
AnalizadaCrítica (9.1)0.41%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to…
AnalizadaMedia (6.1)0.26%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute…
AnalizadaMedia (5.4)0.24%—Bestpractical Request Tracker20/7/202618/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include…
AnalizadaMedia (5.4)0.26%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject…
AnalizadaMedia (6.1)0.26%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session.…
AnalizadaCrítica (9.8)0.61%—Jetbrains Youtrack14/7/202612/8/2026
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
AplazadaAlta (7.6)0.38%—Zorem Advanced Shipment Tracking FOR WoocommerceAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.
AnalizadaMedia (6.1)0.66%—Jetbrains Youtrack10/7/202610/7/2026
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
AnalizadaBaja (3.5)0.23%—Jetbrains Youtrack10/7/202610/7/2026
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
AnalizadaCrítica (9.8)0.34%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
AnalizadaMedia (5.3)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
AnalizadaMedia (5.3)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
AnalizadaAlta (7.5)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
AnalizadaMedia (5.3)0.24%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
AnalizadaAlta (7.5)0.30%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
AplazadaAlta (7.5)0.42%—Johnson AND Johnson Audit Tracking Management SystemAI26/6/202626/6/2026
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
AplazadaCrítica (9.2)0.41%—Setracker2 Android Companion APPAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
AplazadaAlta (8.7)0.26%—Tgelec Setracker2AI26/6/20263/8/2026
The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed,…
AplazadaAlta (8.7)0.39%—Tgelec Setracker2AI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.
AplazadaAlta (8.3)0.35%—Tgelec SetrackerAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging…
Orbitaley — Vulnerabilidades