Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.49%—Mantis BUG TrackerAI19/5/202624/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current one, the clone form (bug_report_page.php) prepends the source Project name before the category selector without proper…
AplazadaMedia (5.3)0.41%—Mantis BUG TrackerAI19/5/202624/7/2026
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global profile despite not having manage_global_profile_threshold, by tampering with the user_id parameter in a valid profile…
AnalizadaCrítica (9.6)1.2%—Ivanti Xtraction12/5/202617/6/2026
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AnalizadaMedia (5.4)0.24%—Traccar5/5/202617/6/2026
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafted HTML in these…
AnalizadaMedia (5.4)0.27%—Traccar5/5/202617/6/2026
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML content into exported…
AnalizadaMedia (6.5)0.35%—Traccar5/5/202617/6/2026
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager…
AnalizadaMedia (4.8)0.18%—Draugiemgroup Desktime Time Tracking28/4/20267/10/2026
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve…
AnalizadaMedia (5.1)0.30%—Jpcert Logontracer27/4/202617/6/2026
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.
AnalizadaAlta (8.7)2.3%—Jpcert Logontracer27/4/202617/6/2026
An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.
AnalizadaMedia (6.5)0.39%—Oracle Peoplesoft Enterprise FIN Contracts21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks…
AnalizadaAlta (7.2)0.54%—Jetbrains Youtrack17/4/202617/6/2026
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
AplazadaMedia (5.5)0.41%—Phpgurukul Daily Expense Tracking SystemAI13/4/202617/6/2026
A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
AplazadaMedia (5.3)0.29%—Anytrack Affiliate Link ManagerAI8/4/202624/7/2026
Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyTrack Affiliate Link Manager: from n/a through <= 1.5.5.
AplazadaMedia (5.3)0.29%—Adastracrypto Cryptocurrency Donation BOXAI8/4/202624/7/2026
Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13.
AplazadaMedia (5.3)0.29%—Rustaurius Order TrackingAI8/4/202624/7/2026
Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.
AplazadaAlta (7.4)0.13%—Lakeside Systtrack AgentAI1/4/202617/6/2026
Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.
AnalizadaCrítica (9.3)0.99%—Datadog Dd-trace-java27/3/202617/6/2026
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port…
AplazadaAlta (7.5)0.28%—Arni Cinco Wpcargo Track AND TraceAI25/3/202617/6/2026
Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.
AnalizadaCrítica (9.8)3.6%💥 PoCDbashford Textract25/3/202617/6/2026
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization
AplazadaMedia (6.1)0.38%—Itracker360AI21/3/202617/6/2026
The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing output escaping. This…
AnalizadaMedia (6.9)0.44%—Trane Tracer SC+ FirmwareTrane Tracer SC FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
AnalizadaAlta (8.2)0.48%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
AnalizadaMedia (6.9)0.42%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
AnalizadaAlta (8.7)0.49%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition