Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.2)0.35%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
AplazadaAlta (8.8)0.29%—GPS Tracking SystemAI6/3/202617/6/2026
GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit crafted POST requests to the login.php endpoint with SQL injection payloads in the username field to gain…
AplazadaAlta (8.8)0.23%—Warranty Tracking SystemAI6/3/202617/6/2026
Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerName, and txtPhone POST parameters in SearchCustomer.php. Attackers can submit crafted SQL statements using UNION SELECT to…
AnalizadaMedia (5.3)0.38%—Thegraph Graph Protocol Contracts5/3/202617/6/2026
The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0.
AplazadaCrítica (9.3)0.42%—Loopus WP Attractive Donations SystemAI5/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from…
AnalizadaMedia (5.3)0.35%—Jetbrains Youtrack25/2/202617/6/2026
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
AnalizadaBaja (2.1)0.43%—Remyandrade Website Link Extractor25/2/202617/6/2026
A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AnalizadaAlta (8.7)0.18%—Traccar23/2/202617/6/2026
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `redirect_uri` parameter is not validated against a whitelist,…
AnalizadaAlta (8.7)0.39%—Traccar23/2/202617/6/2026
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without sanitization and serves…
AnalizadaMedia (6.5)0.33%—Traccar23/2/202617/6/2026
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar uses that `uniqueId` to build the filesystem path without enforcing…
AnalizadaMedia (6.5)0.55%💥 ExploitTraccar23/2/202617/6/2026
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypass the Same Origin…
AplazadaBaja (1.9)0.17%—CcextractorAI21/2/202617/6/2026
A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address…
ModificadaCrítica (9.8)0.46%—Fabian Scholars Tracking System18/2/20268/9/2026
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password,…
ModificadaAlta (8.8)0.72%—Fabian Scholars Tracking System18/2/20268/9/2026
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without…
AplazadaAlta (7.1)0.19%💥 PoCM-track DUO HDAI12/2/202617/6/2026
The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrator privileges.
AplazadaMedia (4.3)0.17%—MMA Call TrackingAI11/2/202617/6/2026
The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.15. This is due to missing nonce validation when saving plugin configuration on the `mma_call_tracking_menu` admin page. This makes it possible for unauthenticated attackers to modify call…
AplazadaAlta (8.8)0.28%—Dinibh Puzzle Software Solutions Dinibh Patrol Tracking SystemAI10/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation of Trusted Identifiers. This issue affects Dinibh Patrol Tracking System: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond…
AplazadaBaja (1.9)0.15%—CcextractorAI9/2/202617/6/2026
A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available…
AnalizadaMedia (6.5)1.3%—Jetbrains Youtrack9/2/202617/6/2026
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
AplazadaMedia (5.3)0.34%—Magic Import Document ExtractorAI4/2/202617/6/2026
The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from the page source on…
AplazadaMedia (5.3)0.34%—Magic Import Document ExtractorAI4/2/202617/6/2026
The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to modify the plugin's license status and…
AnalizadaMedia (4.3)0.44%—Articentgroup ZIP RAR Extractor Tool3/2/202617/6/2026
Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.
AplazadaMedia (4.3)0.21%—Approveme WP Forms Signature Contract ADD ONAI3/2/202617/6/2026
Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through <= 1.8.2.
AplazadaBaja (2.7)0.39%—Wikimedia TextextractsAI3/2/202617/6/2026
Vulnerability in Wikimedia Foundation TextExtracts. This vulnerability is associated with program files includes/ApiQueryExtracts.Php. This issue affects TextExtracts: from * before 1.39.14, 1.43.4, 1.44.1.
AnalizadaMedia (5.5)0.43%—Simsong Bulk Extractor28/1/202617/6/2026
`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under ASAN (and likely a…
Orbitaley — Vulnerabilidades