Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.7)0.66%—Villatheme Orders Tracking FOR Woocommerce4/9/202317/6/2026
The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first…
ModificadaMedia (4.8)0.34%—Etoilewebdesign Order Tracking31/8/202317/6/2026
The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web…
ModificadaMedia (6.1)0.55%—Etoilewebdesign Order Tracking31/8/202317/6/2026
The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
ModificadaMedia (4.3)0.25%—Mooveagency User Activity Tracking AND LOG30/8/202317/6/2026
The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks
ModificadaCrítica (9.8)0.63%—A2technology Camera Trap Tracking System8/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection. This issue affects Camera Trap Tracking System: before 3.1905.
ModificadaMedia (6.5)0.32%—Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+631/7/202317/6/2026
The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts…
ModificadaCrítica (9.8)0.88%—Yontemizleme Vehicle Tracking System10/7/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8.
ModificadaMedia (6.5)0.65%—Zorem Advanced Shipment Tracking FOR Woocommerce7/6/202317/6/2026
The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5…
ModificadaAlta (8.8)0.26%—Zorem Advanced Shipment Tracking FOR Woocommerce25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions.
ModificadaCrítica (9.8)0.62%—Ipekyolunet Software Auto Damage Tracking Software24/5/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4.
ModificadaAlta (8.8)0.85%—Armoli Cargo Tracking System24/5/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass. This issue affects Cargo Tracking System: before 3558f28 .
ModificadaMedia (5.4)0.44%—Timesheets-for-jira Timesheet Tracking17/4/202317/6/2026
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
ModificadaCrítica (9.8)0.83%—Databank Accreditation Tracking/presentation Module21/9/202217/6/2026
Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
ModificadaMedia (6.1)0.37%—Callrail Phone Call Tracking1/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail Phone Call Tracking plugin <= 0.4.9 at WordPress.
ModificadaMedia (4.8)1.4%—Microsoft Advertising Universal Event Tracking1/8/202217/6/2026
The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted…
ModificadaMedia (4.8)0.62%—Chrsinteractive Simple Tracking14/3/202217/6/2026
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (6.1)0.89%—Villatheme Orders Tracking FOR Woocommerce24/1/202217/6/2026
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)2.3%—Mitsubishielectric Qj71mes96 FirmwareMitsubishielectric Qj71ws96 FirmwareMitsubishielectric Q06ccpu-v FirmwareMitsubishielectric Q24dhccpu-v Firmware+915/10/202017/6/2026
Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.
ModificadaAlta (8.8)1.3%—Hutchhouse Marketo Forms AND Tracking21/1/202017/6/2026
The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (6.1)0.95%—Ithemes Custom URL Tracking28/8/201917/6/2026
Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaCrítica (9.8)6.6%💥 ExploitGps-server GPS Tracking Software2/1/201817/6/2026
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
ModificadaCrítica (9.8)6.9%💥 ExploitGps-server GPS Tracking Software2/1/201817/6/2026
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new…
ModificadaMedia (6.8)1.0%—Tracking Code Project Tracking Code15/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in tracking_code.admin.inc in the Tracking Code module 7.x-1.x before 7.x-1.6 for Drupal allows remote attackers to hijack the authentication of administrators for requests that disable tracking codes via unspecified vectors.
ModificadaMedia (6.8)0.91%💥 ExploitZentracking ZEN Time Tracking23/3/201016/6/2026
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of these details are obtained from third…
Orbitaley — Vulnerabilidades