Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.37% | — | Kromit TitraAI | 4/5/2026 | 17/6/2026 | titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and google_clientid. At… | |
| Analizada | Media (4.3) | 0.29% | — | Kromit Titra | 8/1/2026 | 17/6/2026 | Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authenticated users to inject arbitrary fields into time entries, bypassing business logic controls via the customfields parameter. The affected endpoint uses the JavaScript… | |
| Analizada | Alta (8.1) | 0.28% | — | Kromit Titra | 8/1/2026 | 17/6/2026 | Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50. | |
| Analizada | Crítica (9.1) | 0.85% | — | Kromit Titra | 31/12/2025 | 23/9/2026 | Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue. | |
| Modificada | Media (6.1) | 0.34% | — | RWS Multitrans | 18/9/2024 | 17/6/2026 | An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail. | |
| Modificada | Media (6.1) | 0.34% | — | RWS Multitrans | 18/9/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Crítica (10) | 1.3% | — | Kromit Titra | 1/8/2022 | 17/6/2026 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. | |
| Modificada | Crítica (9.8) | 1.0% | — | Kromit Titra | 16/6/2022 | 17/6/2026 | Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. | |
| Modificada | Media (5.4) | 0.71% | — | Kromit Titra | 9/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. | |
| Modificada | Media (5.4) | 0.71% | — | Kromit Titra | 9/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. | |
| Modificada | Alta (8) | 1.2% | — | Kromit Titra | 9/6/2022 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. | |
| Modificada | Media (5.4) | 0.71% | — | Kromit Titra | 9/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. | |
| Modificada | Alta (7.4) | 0.51% | — | Avast AntitrackAvast AVG Antitrack | 9/3/2020 | 17/6/2026 | Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using AntiTrack with "Allow filtering of HTTPS… | |
| Modificada | Media (5.4) | 0.27% | — | Sourcelink Multitrac | 16/10/2014 | 17/6/2026 | The Multitrac (aka com.multitrac) application 1.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.6% | — | Btitracker Project BtitrackerXbtitracker Project Xbtitracker | 26/8/2008 | 16/6/2026 | SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Btiteam Btitracker | 15/11/2007 | 16/6/2026 | SQL injection vulnerability in include/functions.php in BtiTracker before 1.4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.4) | 1.5% | — | Bti-trackerBtitracker | 7/3/2007 | 16/6/2026 | Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action. | |
| Modificada | Alta (7.5) | 1.5% | — | Btitracker | 7/2/2007 | 16/6/2026 | SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) by and (2) order parameters. NOTE: it is not clear whether this issue is exploitable. |