Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.6)0.22%—Bestpractical Request TrackerAI16/1/202617/6/2026
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
AnalizadaMedia (6.9)0.57%—Smartertools Smartertrack16/1/202617/6/2026
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.
AplazadaMedia (6.5)0.15%—Kcseopro Adwords Conversion Tracking CodeAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kcseopro AdWords Conversion Tracking Code adwords-conversion-tracking-code allows Stored XSS.This issue affects AdWords Conversion Tracking Code: from n/a through <= 1.0.
AnalizadaMedia (5.5)0.39%—Fabian Scholars Tracking System19/12/202517/6/2026
A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /home.php. Such manipulation of the argument post_content leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be…
ModificadaMedia (5.5)0.39%—Fabian Scholars Tracking System19/12/202517/6/2026
A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could…
AnalizadaMedia (5.5)0.39%—Fabian Scholars Tracking System19/12/202517/6/2026
A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /admin/delete_user.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be…
AnalizadaAlta (7.3)0.20%—Angeljudesuarez Covid Tracking System Using Qr-code17/12/202517/6/2026
A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleaning or validation.
AplazadaAlta (7)0.35%—Asrock MotherboardAIAsrockrack MotherboardAIAsrocind MotherboardAI17/12/20257/10/2026
Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel…
AnalizadaMedia (5.5)0.39%—Angeljudesuarez Covid Tracking System14/12/202528/9/2026
A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation of the argument meta_value leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.39%—Angeljudesuarez Covid Tracking System14/12/202528/9/2026
A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and…
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Covid Tracking System12/12/202517/6/2026
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=zone. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.39%—Angeljudesuarez Covid Tracking System12/12/202517/6/2026
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…
AplazadaBaja (3.5)0.11%—Mediawiki TableprogresstrackingAI11/12/202517/6/2026
TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user on a wiki with the extension enabled, would…
AplazadaAlta (7.1)0.17%—Handl UTM Grabber TrackerAI10/12/202525/9/2026
The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaAlta (7.1)0.17%—Handl UTM Grabber TrackerAI10/12/202525/9/2026
The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (5.3)0.30%—Wpgoaltracker WP Google Analytics EventsAI9/12/20255/10/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in yuvalo WP Google Analytics Events wp-google-analytics-events allows Retrieve Embedded Sensitive Data.This issue affects WP Google Analytics Events: from n/a through <= 2.8.2.
AplazadaAlta (7.4)0.34%—Sunbirddcim DctrackAI4/12/202517/6/2026
DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.
AplazadaAlta (8.4)0.13%—Sunbirddcim DctrackAI4/12/202525/9/2026
DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.
ModificadaMedia (5.5)0.39%—Angeljudesuarez Covid Tracking System24/11/202517/6/2026
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
AnalizadaBaja (2.1)0.31%—Angeljudesuarez Covid Tracking System23/11/202517/6/2026
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=state. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalizadaBaja (2.1)0.31%—Angeljudesuarez Covid Tracking System23/11/202517/6/2026
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/?page=city. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2.1)0.31%—Angeljudesuarez Covid Tracking System23/11/202517/6/2026
A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AnalizadaBaja (2.1)0.31%—Angeljudesuarez Covid Tracking System23/11/202530/9/2026
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This affects an unknown function of the file /admin/?page=establishment. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AplazadaMedia (4.8)0.22%—Owasp Dependency-trackAI17/11/202517/6/2026
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a…
ModificadaBaja (3.7)0.21%—Jetbrains Youtrack11/11/202517/6/2026
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
Orbitaley — Vulnerabilidades