Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.49% | — | Mantis BUG TrackerAI | 19/5/2026 | 24/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current one, the clone form (bug_report_page.php) prepends the source Project name before the category selector without proper… | |
| Aplazada | Media (5.3) | 0.41% | — | Mantis BUG TrackerAI | 19/5/2026 | 24/7/2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global profile despite not having manage_global_profile_threshold, by tampering with the user_id parameter in a valid profile… | |
| Analizada | Crítica (9.6) | 1.2% | — | Ivanti Xtraction | 12/5/2026 | 17/6/2026 | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Media (5.4) | 0.24% | — | Traccar | 5/5/2026 | 17/6/2026 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafted HTML in these… | |
| Analizada | Media (5.4) | 0.27% | — | Traccar | 5/5/2026 | 17/6/2026 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML content into exported… | |
| Analizada | Media (6.5) | 0.35% | — | Traccar | 5/5/2026 | 17/6/2026 | Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager… | |
| Analizada | Media (4.8) | 0.18% | — | Draugiemgroup Desktime Time Tracking | 28/4/2026 | 7/10/2026 | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve… | |
| Analizada | Media (5.1) | 0.30% | — | Jpcert Logontracer | 27/4/2026 | 17/6/2026 | There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered. | |
| Analizada | Alta (8.7) | 2.3% | — | Jpcert Logontracer | 27/4/2026 | 17/6/2026 | An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Contracts | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks… | |
| Analizada | Alta (7.2) | 0.54% | — | Jetbrains Youtrack | 17/4/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | |
| Aplazada | Media (5.5) | 0.41% | — | Phpgurukul Daily Expense Tracking SystemAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Media (5.3) | 0.29% | — | Anytrack Affiliate Link ManagerAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyTrack Affiliate Link Manager: from n/a through <= 1.5.5. | |
| Aplazada | Media (5.3) | 0.29% | — | Adastracrypto Cryptocurrency Donation BOXAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13. | |
| Aplazada | Media (5.3) | 0.29% | — | Rustaurius Order TrackingAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3. | |
| Aplazada | Alta (7.4) | 0.13% | — | Lakeside Systtrack AgentAI | 1/4/2026 | 17/6/2026 | Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15. | |
| Analizada | Crítica (9.3) | 0.99% | — | Datadog Dd-trace-java | 27/3/2026 | 17/6/2026 | dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port… | |
| Aplazada | Alta (7.5) | 0.28% | — | Arni Cinco Wpcargo Track AND TraceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2. | |
| Analizada | Crítica (9.8) | 3.6% | 💥 PoC | Dbashford Textract | 25/3/2026 | 17/6/2026 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization | |
| Aplazada | Media (6.1) | 0.38% | — | Itracker360AI | 21/3/2026 | 17/6/2026 | The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing output escaping. This… | |
| Analizada | Media (6.9) | 0.44% | — | Trane Tracer SC+ FirmwareTrane Tracer SC FirmwareTrane Tracer Concierge | 12/3/2026 | 17/6/2026 | A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts. | |
| Analizada | Alta (8.2) | 0.48% | — | Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge | 12/3/2026 | 17/6/2026 | A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts. | |
| Analizada | Media (6.9) | 0.42% | — | Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge | 12/3/2026 | 17/6/2026 | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs. | |
| Analizada | Alta (8.7) | 0.49% | — | Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge | 12/3/2026 | 17/6/2026 | A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition |