Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1387 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.27% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | |
| Aplazada | Alta (8.1) | 0.35% | — | Jetbrains YoutrackAI | 7/9/2026 | 9/9/2026 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | |
| Aplazada | Crítica (9.8) | 0.61% | — | Jetbrains YoutrackAI | 7/9/2026 | 9/9/2026 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | |
| Aplazada | Alta (8.8) | 0.42% | — | Jetbrains YoutrackAI | 7/9/2026 | 22/9/2026 | In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation | |
| Aplazada | Baja (2.1) | 0.22% | — | Toggl Track ExtensionAI | 31/8/2026 | 31/8/2026 | A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The… | |
| Aplazada | Alta (7.5) | 0.79% | — | Datadog DD Trace RSAI | 28/8/2026 | 9/9/2026 | dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Micrometer TracingAI | 21/8/2026 | 28/8/2026 | An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer Tracing 1.5.0 - 1.5.12 Micrometer Tracing… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Service Contracts | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Contracts. Successful… | |
| Aplazada | Baja (2.1) | 0.59% | — | Sonos TractAI | 18/8/2026 | 20/8/2026 | A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (8.1) | 0.35% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | |
| Analizada | Media (6.5) | 1.1% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | |
| Analizada | Alta (8.2) | 0.32% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | |
| Analizada | Media (6.5) | 1.2% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | |
| Analizada | Crítica (9.1) | 0.42% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | |
| Analizada | Alta (8.1) | 0.38% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | |
| Aplazada | Alta (8.1) | 0.28% | — | Max-mapper Extract-zipAI | 17/8/2026 | 9/9/2026 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and… | |
| Aplazada | Media (6.6) | 0.52% | — | Openzeppelin Confidential ContractsAIZama FhevmAI | 13/8/2026 | 18/9/2026 | OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint operation could fail silently. The wrap and onTransferReceived functions in… | |
| Pendiente de análisis | Media (5.7) | 0.11% | — | Elan Trackpoint DriverAI | 13/8/2026 | 24/8/2026 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash. | |
| Aplazada | Media (6.5) | 0.22% | — | Aftership TrackingAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Aplazada | Crítica (9.3) | 0.67% | — | React-trackedAI | 10/8/2026 | 9/9/2026 | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e742627e8 that executed remote attacker-controlled code on developer machines… | |
| Aplazada | Alta (8.8) | 0.64% | — | Openzeppelin Contracts WizardAIHardhatAI | 6/8/2026 | 14/9/2026 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string… | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. |