Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.71% | — | Ivanti Xtraction | 14/7/2026 | 6/8/2026 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. | |
| Analizada | Crítica (9.8) | 0.61% | — | Jetbrains Youtrack | 14/7/2026 | 12/8/2026 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | |
| Aplazada | Alta (7.6) | 0.38% | — | Zorem Advanced Shipment Tracking FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0. | |
| Analizada | Media (6.1) | 0.66% | — | Jetbrains Youtrack | 10/7/2026 | 10/7/2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | |
| Analizada | Baja (3.5) | 0.23% | — | Jetbrains Youtrack | 10/7/2026 | 10/7/2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dbix QuickormAISQL AbstractAI | 30/6/2026 | 30/6/2026 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys,… | |
| Analizada | Alta (8.6) | 0.53% | 💥 PoC | Max-mapper Extract-zip | 26/6/2026 | 6/7/2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how… | |
| Analizada | Crítica (9.8) | 0.34% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details | |
| Analizada | Alta (7.5) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | |
| Analizada | Media (5.3) | 0.24% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | |
| Analizada | Alta (7.5) | 0.30% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | |
| Aplazada | Alta (7.5) | 0.42% | — | Johnson AND Johnson Audit Tracking Management SystemAI | 26/6/2026 | 26/6/2026 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts. | |
| Aplazada | Crítica (9.2) | 0.41% | — | Setracker2 Android Companion APPAI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access. | |
| Aplazada | Alta (8.7) | 0.26% | — | Tgelec Setracker2AI | 26/6/2026 | 3/8/2026 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed,… | |
| Aplazada | Alta (8.7) | 0.39% | — | Tgelec Setracker2AI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic. | |
| Aplazada | Alta (8.3) | 0.35% | — | Tgelec SetrackerAI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging… | |
| Analizada | Crítica (9.8) | 1.2% | — | Rapid7 Insightconnect Traceroute | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands. | |
| Pendiente de análisis | Media (5.1) | 0.49% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 24/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 22/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own… | |
| Aplazada | Media (4.7) | 0.08% | — | Steeltoe Configuration AbstractionsAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Traccar ClientAI | 17/6/2026 | 17/6/2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Advanced ADS TrackingAI | 17/6/2026 | 6/10/2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | |
| Pendiente de análisis | Media (5.6) | 0.14% | — | Gnome Tracker-extract-mp3AIGnome Tracker-minersAI | 16/6/2026 | 17/6/2026 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)… |