Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.22%—Jetbrains Youtrack10/11/202517/6/2026
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
AnalizadaAlta (7.5)0.31%—Jetbrains Youtrack10/11/202517/6/2026
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
AnalizadaMedia (6.1)0.19%—Plausible Tracking Project Plausible Tracking30/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS).This issue affects Plausible tracking: from 0.0.0 before 1.0.2.
AplazadaBaja (2.1)0.29%—Axosoft Scrum AND BUG TrackingAI27/10/202517/6/2026
A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing manipulation of the argument Title results in csv injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.…
AplazadaMedia (4.3)0.31%—Epiphanyit321 Referral Link TrackerAI27/10/202517/6/2026
Missing Authorization vulnerability in epiphanyit321 Referral Link Tracker referral-link-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Referral Link Tracker: from n/a through <= 1.1.4.
AplazadaMedia (5.3)0.45%—Request TrackerAI24/10/202517/6/2026
The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the ticket in the…
AplazadaAlta (7.1)0.24%—Mithra62 Wp-click-trackerAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mithra62 WP-Click-Tracker wp-click-track allows Reflected XSS.This issue affects WP-Click-Tracker: from n/a through <= 0.7.3.
AplazadaMedia (4.9)0.37%—Email TrackerAI22/10/202517/6/2026
The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient…
AplazadaCrítica (9.8)0.37%—Cats Information Technology Software Development Technologies Aykome License Tracking SystemAI13/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows SQL Injection. This issue affects Aykome License Tracking System: before Version dated 06.10.2025.
AnalizadaAlta (7.5)0.65%—Rack10/10/202517/6/2026
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`, calling `rack.input.read(nil)` without enforcing a length or cap. Large request bodies can therefore be…
AnalizadaMedia (5.3)0.55%—Rack10/10/202517/6/2026
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers (such as Nginx). Specially crafted headers could cause `Rack::Sendfile` to miscommunicate…
AplazadaMedia (4.7)0.28%—Owasp Dependency-trackAI7/10/202517/6/2026
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.13.5, Dependency-Track may send credentials meant for a private NuGet repository to `api.nuget.org` via the HTTP `Authorization` header, and may disclose names and…
AnalizadaAlta (7.5)0.93%—Rack7/10/202517/6/2026
Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header block never terminates with the required blank line (`CRLFCRLF`). The parser keeps appending incoming bytes to memory without a size cap,…
AnalizadaAlta (7.5)0.56%—Rack7/10/202517/6/2026
Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can…
AnalizadaAlta (7.5)0.93%—Rack7/10/202517/6/2026
Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the first boundary) in memory without any size limit. A client can send a large preamble followed by a valid boundary, causing significant memory…
AplazadaBaja (2)0.23%—Axosoft Scrum AND BUG TrackingAI5/10/202517/6/2026
A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing of the component Add Work Item Page. The manipulation of the argument Title results in csv injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was…
AnalizadaAlta (7.5)0.57%—Rack25/9/202517/6/2026
Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended.…
AplazadaAlta (8.8)0.36%—Time TrackerAI11/9/202517/6/2026
The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_function' and 'tt_delete_record_function' functions in all versions up to, and including, 3.1.0. This makes it possible for authenticated attackers, with…
AnalizadaBaja (2)0.29%—Rems Personal Time Tracker8/9/202517/6/2026
A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.
AplazadaMedia (5.9)0.19%—Rbaer Simple Matomo Tracking CodeAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0.
AnalizadaMedia (4.2)0.32%💥 PoCDonbermoy Android Corona Virus Tracker APP FOR India3/9/202517/6/2026
The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes…
AnalizadaBaja (2.4)0.26%💥 PoCMeitrack T366l-g Firmware28/8/202525/9/2026
Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive…
AplazadaMedia (5.9)0.22%—Vikingjs Goal Tracker FOR PatreonAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon goal-tracker-for-patreon allows Stored XSS.This issue affects Goal Tracker for Patreon: from n/a through <= 0.4.6.
AplazadaMedia (5.3)0.22%—Aftership TrackingAIAftership Woocommerce TrackingAI27/8/202517/6/2026
Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AfterShip Tracking: from n/a through <= 1.17.17.
AnalizadaMedia (5.4)0.28%—Jetbrains Youtrack20/8/202517/6/2026
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
Orbitaley — Vulnerabilidades