Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.37%—Kromit TitraAI4/5/202617/6/2026
titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and google_clientid. At…
AnalizadaMedia (4.3)0.29%—Kromit Titra8/1/202617/6/2026
Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authenticated users to inject arbitrary fields into time entries, bypassing business logic controls via the customfields parameter. The affected endpoint uses the JavaScript…
AnalizadaAlta (8.1)0.28%—Kromit Titra8/1/202617/6/2026
Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50.
AnalizadaCrítica (9.1)0.85%—Kromit Titra31/12/202523/9/2026
Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
ModificadaMedia (6.1)0.34%—RWS Multitrans18/9/202417/6/2026
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.
ModificadaMedia (6.1)0.34%—RWS Multitrans18/9/202417/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaCrítica (10)1.3%—Kromit Titra1/8/202217/6/2026
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
ModificadaCrítica (9.8)1.0%—Kromit Titra16/6/202217/6/2026
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
ModificadaMedia (5.4)0.71%—Kromit Titra9/6/202217/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
ModificadaMedia (5.4)0.71%—Kromit Titra9/6/202217/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
ModificadaAlta (8)1.2%—Kromit Titra9/6/202217/6/2026
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
ModificadaMedia (5.4)0.71%—Kromit Titra9/6/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
ModificadaAlta (7.4)0.51%—Avast AntitrackAvast AVG Antitrack9/3/202017/6/2026
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using AntiTrack with "Allow filtering of HTTPS…
ModificadaMedia (5.4)0.27%—Sourcelink Multitrac16/10/201417/6/2026
The Multitrac (aka com.multitrac) application 1.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.6%—Btitracker Project BtitrackerXbtitracker Project Xbtitracker26/8/200816/6/2026
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
ModificadaAlta (7.5)1.1%—Btiteam Btitracker15/11/200716/6/2026
SQL injection vulnerability in include/functions.php in BtiTracker before 1.4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.4)1.5%—Bti-trackerBtitracker7/3/200716/6/2026
Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action.
ModificadaAlta (7.5)1.5%—Btitracker7/2/200716/6/2026
SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) by and (2) order parameters. NOTE: it is not clear whether this issue is exploitable.