Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

1390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.71%—Ivanti Xtraction14/7/20266/8/2026
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
AnalizadaCrítica (9.8)0.61%—Jetbrains Youtrack14/7/202612/8/2026
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
AplazadaAlta (7.6)0.38%—Zorem Advanced Shipment Tracking FOR WoocommerceAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.
AnalizadaMedia (6.1)0.66%—Jetbrains Youtrack10/7/202610/7/2026
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
AnalizadaBaja (3.5)0.23%—Jetbrains Youtrack10/7/202610/7/2026
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
AplazadaCrítica (9.8)0.55%—Dbix QuickormAISQL AbstractAI30/6/202630/6/2026
DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys,…
AnalizadaAlta (8.6)0.53%💥 PoCMax-mapper Extract-zip26/6/20266/7/2026
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how…
AnalizadaCrítica (9.8)0.34%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
AnalizadaMedia (5.3)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
AnalizadaMedia (5.3)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
AnalizadaAlta (7.5)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
AnalizadaMedia (5.3)0.24%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
AnalizadaAlta (7.5)0.30%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
AplazadaAlta (7.5)0.42%—Johnson AND Johnson Audit Tracking Management SystemAI26/6/202626/6/2026
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
AplazadaCrítica (9.2)0.41%—Setracker2 Android Companion APPAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
AplazadaAlta (8.7)0.26%—Tgelec Setracker2AI26/6/20263/8/2026
The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed,…
AplazadaAlta (8.7)0.39%—Tgelec Setracker2AI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.
AplazadaAlta (8.3)0.35%—Tgelec SetrackerAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging…
AnalizadaCrítica (9.8)1.2%—Rapid7 Insightconnect Traceroute25/6/202629/6/2026
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.
Pendiente de análisisMedia (5.1)0.49%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202624/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access…
Pendiente de análisisAlta (8.7)0.72%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202622/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own…
AplazadaMedia (4.7)0.08%—Steeltoe Configuration AbstractionsAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those…
AplazadaCrítica (9.3)0.41%—Traccar ClientAI17/6/202617/6/2026
Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a…
AplazadaCrítica (9.3)0.40%—Advanced ADS TrackingAI17/6/20266/10/2026
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
Pendiente de análisisMedia (5.6)0.14%—Gnome Tracker-extract-mp3AIGnome Tracker-minersAI16/6/202617/6/2026
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)…