Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

1390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Shipment Tracker FOR WoocommerceAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
AplazadaMedia (4.3)0.11%—Wedevs Woocommerce Conversion TrackingAI11/6/202629/9/2026
Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.
AplazadaMedia (5.5)0.29%—Sourcecodester SEO Meta TAG ExtractorAI1/6/202622/7/2026
A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and…
AplazadaAlta (7.5)0.42%—Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI1/6/202622/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a…
AnalizadaMedia (6.5)0.34%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
AnalizadaMedia (6.5)0.30%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
AnalizadaAlta (7.5)0.33%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
AnalizadaMedia (4.3)0.27%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
AnalizadaMedia (5.4)0.27%—Jetbrains Youtrack29/5/202622/7/2026
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
AplazadaAlta (7.5)0.58%—Mantis BUG TrackerAI28/5/202621/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in…
AplazadaAlta (8.6)0.44%—Mantisbt Mantis BUG TrackerAI28/5/202621/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator access level) to inject HTML in Move Attachments admin page. This vulnerability is fixed in 2.28.2.
AplazadaAlta (7.2)0.43%—Mantis BUG TrackerAI28/5/202617/6/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnotes they should not be able to access, via the REST API endpoint GET…
AplazadaMedia (5.3)0.45%—Mantis BUG TrackerAI28/5/202617/6/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update_bug_threshold access (UPDATER, with default settings) to edit, change view state, and modify time tracking on bugnotes belonging to other users — bypassing the default…
Pendiente de análisisMedia (5.3)0.85%—Opentelemetry-javaAIOpentelemetry-apiAIOpentelemetry-extension-trace-propagatorsAI28/5/202610/9/2026
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized…
AplazadaAlta (8.7)0.54%—SsoabstractserviceAI27/5/202617/6/2026
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
AnalizadaMedia (5.3)0.25%—Traccar26/5/202624/7/2026
Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic mutation path in…
AplazadaAlta (7.5)0.49%—Mantisbt Mantis BUG TrackerAI22/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a saved filter's owner, allowing an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON. Note that By default, only users with…
AplazadaMedia (6.9)0.53%—Mantis BUG TrackerAI22/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters,…
AplazadaAlta (7.6)0.59%—Mantisbt Mantis BUG TrackerAI22/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed via the file_download.php…
AnalizadaMedia (5.1)0.40%—Bestpractical Request Tracker21/5/202623/7/2026
Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up…
AplazadaMedia (5.4)0.29%—Mantis BUG TrackerAI20/5/202623/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom field's contents in the Update Issue page, (bug_update_page.php) allowing an attacker to inject HTML and, if CSP settings permit, execute arbitrary JavaScript…
AplazadaMedia (5.3)0.45%—Mantisbt Mantis BUG TrackerAI20/5/202624/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page after losing access to the parent private issue. This issue has been fixed in version 2.28.2.
AplazadaMedia (4.3)0.33%—Mantisbt Mantis BUG TrackerAI20/5/202624/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.
AplazadaMedia (5.3)0.44%—Mantisbt Mantis BUG TrackerAI19/5/202624/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and download their own attachments from an Issue created by another user even after it becomes private, bypassing read access revocation. The loss of confidentiality caused by this vulnerability is minimal,…
AplazadaMedia (5.3)0.44%—Mantisbt Mantis BUG TrackerAI19/5/202624/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Bypass through the private issue monitoring feature . Using a crafted POST request to bug_monitor_add.php, a user with project-level access can add themselves as a monitor for a private issue they…