Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.9%💥 ExploitScheduling Management.com Time Tracking Software15/2/200616/6/2026
edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.
ModificadaAlta (7.5)1.4%—Scheduling Management.com Time Tracking Software15/2/200616/6/2026
Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.7%💥 ExploitRedkernel Referrer Tracker19/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this information is unknown; portions of the details…
ModificadaMedia (4.3)1.4%—Widexl Download Tracker18/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
ModificadaMedia (5)1.4%—Intracom Jetspeed18/1/200616/6/2026
Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests.
ModificadaMedia (4.3)2.0%💥 ExploitInterspire Trackpoint NX14/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.
ModificadaMedia (5)2.3%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
ModificadaMedia (5)3.4%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
ModificadaMedia (4.3)1.5%—Edgewall Software Trac31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.
ModificadaAlta (10)3.8%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
ModificadaMedia (4.3)1.4%—Edgewall Software Trac17/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.
ModificadaAlta (7.5)4.0%💥 ExploitEdgewall Software Trac7/12/200516/6/2026
SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaAlta (7.5)3.3%💥 ExploitEdgewall Software Trac4/12/200516/6/2026
SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.
ModificadaMedia (6.4)1.4%—Edgewall Software Trac6/7/200516/6/2026
Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.
ModificadaMedia (6.4)1.8%—Edgewall Software Trac19/6/200516/6/2026
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
ModificadaMedia (5)3.3%💥 ExploitDatatrac Activity Console18/5/200516/6/2026
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
ModificadaAlta (7.5)1.1%—Bugtracker.netAI2/5/200516/6/2026
Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (5)1.5%—Trackercam30/3/200516/6/2026
TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos leer ficheros de log mediante el parámetro fn en una consulta directa al script ComGetLogFile.php3.
ModificadaMedia (4.3)1.2%—Trackercam30/3/200516/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos inyectar código HTML arbitrario o script mediante una petición de conexión, la cual es almacenada en un fichero de log pero que no se maneja adecuadamente cuando el administrador visualiza…
ModificadaMedia (5)1.7%—Trackercam30/3/200516/6/2026
TrackerCam 5.12 y versiones anteriores permiten a atacantes remotos causar la Denegación de Servicio (DoS) por caída, mediante: un gran número de conexiones con una cabecera Content-Length negativa, posiblemente provocando un error de entero sin signo, una gran cantidad de datos.
ModificadaMedia (5)66%💥 ExploitTrackercam30/3/200516/6/2026
Múltiples desbordamientos de búfer en TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos causar la Denegación de Servicios (DoS) y posiblemente la ejecución de código arbitrario mediante: una petición HTTP con una cabecera User-Agent larga, un argumento largo a un script PHP arbitrario
ModificadaMedia (5)3.1%💥 ExploitTrackercam30/3/200516/6/2026
Atravesamiento de directorios en ComGetLogFile.php3 de TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos la lectura de ficheros arbitrarios mediante secuencias "".."" y: ""/"" slash), """" (backslash), caracteres hexadecimales en el parámetro fn.
ModificadaMedia (5)3.6%—Cabextract Project Cabextract27/1/200516/6/2026
Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.
ModificadaMedia (5.8)2.2%💥 ExploitSerena Software Serena Teamtrack31/12/200416/6/2026
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.
ModificadaAlta (7.5)14%💥 ExploitCvstrac31/12/200416/6/2026
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.