Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.26%—Tgelec Setracker2AI26/6/20263/8/2026
The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed,…
AplazadaAlta (8.7)0.39%—Tgelec Setracker2AI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.
AplazadaAlta (8.3)0.35%—Tgelec SetrackerAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging…
AnalizadaMedia (6.1)0.15%—Dell Powerflex Rack Release Certification Matrix17/6/20266/10/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.
AplazadaCrítica (9.3)0.40%—Advanced ADS TrackingAI17/6/20266/10/2026
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
Pendiente de análisisMedia (5.6)0.14%—Gnome Tracker-extract-mp3AIGnome Tracker-minersAI16/6/202617/6/2026
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)…
AplazadaMedia (6.5)0.22%—Shipment Tracker FOR WoocommerceAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
AplazadaMedia (4.3)0.11%—Wedevs Woocommerce Conversion TrackingAI11/6/202629/9/2026
Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.
AplazadaAlta (7.5)0.42%—Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI1/6/202622/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a…
AplazadaAlta (8.8)0.97%💥 PoCBracketspace SpectraAI30/5/202622/7/2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation…
AnalizadaMedia (6.5)0.34%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
AnalizadaMedia (6.5)0.30%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
AnalizadaAlta (7.5)0.33%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
AnalizadaMedia (4.3)0.27%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
AnalizadaMedia (5.4)0.27%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
AplazadaAlta (7.5)0.58%—Mantis BUG TrackerAI28/5/202621/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in…
AplazadaAlta (8.6)0.44%—Mantisbt Mantis BUG TrackerAI28/5/202621/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator access level) to inject HTML in Move Attachments admin page. This vulnerability is fixed in 2.28.2.
AplazadaAlta (7.2)0.43%—Mantis BUG TrackerAI28/5/202617/6/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnotes they should not be able to access, via the REST API endpoint GET…
AplazadaMedia (5.3)0.45%—Mantis BUG TrackerAI28/5/202617/6/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update_bug_threshold access (UPDATER, with default settings) to edit, change view state, and modify time tracking on bugnotes belonging to other users — bypassing the default…
AplazadaAlta (7.5)0.49%—Mantisbt Mantis BUG TrackerAI22/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a saved filter's owner, allowing an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON. Note that By default, only users with…
AplazadaMedia (6.9)0.53%—Mantis BUG TrackerAI22/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters,…
AplazadaAlta (7.6)0.59%—Mantisbt Mantis BUG TrackerAI22/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed via the file_download.php…
AnalizadaAlta (8.2)0.17%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/202623/7/2026
Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing…
AnalizadaMedia (5.5)0.07%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AnalizadaMedia (5.5)0.10%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack22/5/20265/10/2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.