Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.26% | — | Tgelec Setracker2AI | 26/6/2026 | 3/8/2026 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed,… | |
| Aplazada | Alta (8.7) | 0.39% | — | Tgelec Setracker2AI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic. | |
| Aplazada | Alta (8.3) | 0.35% | — | Tgelec SetrackerAI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging… | |
| Analizada | Media (6.1) | 0.15% | — | Dell Powerflex Rack Release Certification Matrix | 17/6/2026 | 6/10/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Advanced ADS TrackingAI | 17/6/2026 | 6/10/2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | |
| Pendiente de análisis | Media (5.6) | 0.14% | — | Gnome Tracker-extract-mp3AIGnome Tracker-minersAI | 16/6/2026 | 17/6/2026 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)… | |
| Aplazada | Media (6.5) | 0.22% | — | Shipment Tracker FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions. | |
| Aplazada | Media (4.3) | 0.11% | — | Wedevs Woocommerce Conversion TrackingAI | 11/6/2026 | 29/9/2026 | Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10. | |
| Aplazada | Alta (7.5) | 0.42% | — | Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI | 1/6/2026 | 22/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a… | |
| Aplazada | Alta (8.8) | 0.97% | 💥 PoC | Bracketspace SpectraAI | 30/5/2026 | 22/7/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation… | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | |
| Analizada | Media (6.5) | 0.30% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | |
| Analizada | Alta (7.5) | 0.33% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | |
| Aplazada | Alta (7.5) | 0.58% | — | Mantis BUG TrackerAI | 28/5/2026 | 21/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in… | |
| Aplazada | Alta (8.6) | 0.44% | — | Mantisbt Mantis BUG TrackerAI | 28/5/2026 | 21/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator access level) to inject HTML in Move Attachments admin page. This vulnerability is fixed in 2.28.2. | |
| Aplazada | Alta (7.2) | 0.43% | — | Mantis BUG TrackerAI | 28/5/2026 | 17/6/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnotes they should not be able to access, via the REST API endpoint GET… | |
| Aplazada | Media (5.3) | 0.45% | — | Mantis BUG TrackerAI | 28/5/2026 | 17/6/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update_bug_threshold access (UPDATER, with default settings) to edit, change view state, and modify time tracking on bugnotes belonging to other users — bypassing the default… | |
| Aplazada | Alta (7.5) | 0.49% | — | Mantisbt Mantis BUG TrackerAI | 22/5/2026 | 23/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a saved filter's owner, allowing an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON. Note that By default, only users with… | |
| Aplazada | Media (6.9) | 0.53% | — | Mantis BUG TrackerAI | 22/5/2026 | 23/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters,… | |
| Aplazada | Alta (7.6) | 0.59% | — | Mantisbt Mantis BUG TrackerAI | 22/5/2026 | 23/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed via the file_download.php… | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing… | |
| Analizada | Media (5.5) | 0.07% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 5/10/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Media (5.5) | 0.10% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 5/10/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. |