Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.53% | — | TraccarAI | 17/9/2026 | 24/9/2026 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. org.traccar.api.resource.GroupResource permits the parent cycle,… | |
| Aplazada | Alta (7.1) | 0.39% | — | TraccarAI | 17/9/2026 | 30/9/2026 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedHashMap<String, Long>) in… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Traccar ClientAI | 17/6/2026 | 17/6/2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a… | |
| Analizada | Media (5.3) | 0.25% | — | Traccar | 26/5/2026 | 24/7/2026 | Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic mutation path in… | |
| Analizada | Media (5.4) | 0.24% | — | Traccar | 5/5/2026 | 17/6/2026 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafted HTML in these… | |
| Analizada | Media (5.4) | 0.27% | — | Traccar | 5/5/2026 | 17/6/2026 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML content into exported… | |
| Analizada | Media (6.5) | 0.35% | — | Traccar | 5/5/2026 | 17/6/2026 | Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager… | |
| Analizada | Alta (8.7) | 0.18% | — | Traccar | 23/2/2026 | 17/6/2026 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `redirect_uri` parameter is not validated against a whitelist,… | |
| Analizada | Alta (8.7) | 0.39% | — | Traccar | 23/2/2026 | 17/6/2026 | Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without sanitization and serves… | |
| Analizada | Media (6.5) | 0.33% | — | Traccar | 23/2/2026 | 17/6/2026 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar uses that `uniqueId` to build the filesystem path without enforcing… | |
| Analizada | Media (6.5) | 0.55% | — | Traccar | 23/2/2026 | 17/6/2026 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypass the Same Origin… | |
| Aplazada | Alta (8.7) | 1.3% | — | TraccarAI | 2/10/2025 | 17/6/2026 | Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the… | |
| Analizada | Crítica (9.5) | 0.53% | — | Traccar | 13/8/2024 | 17/6/2026 | Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication mechanism. These transactions could have… | |
| Analizada | Crítica (9.6) | 18% | — | Traccar | 10/4/2024 | 17/6/2026 | Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. Attackers have full control over the file contents, full control over the directory where the file is stored, full control over the file extension, and partial… | |
| Aplazada | Alta (8.5) | 54% | — | TraccarAI | 10/4/2024 | 17/6/2026 | Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload… | |
| Modificada | Crítica (9.8) | 0.60% | — | Traccar | 15/1/2024 | 17/6/2026 | Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary code on the server. This vulnerability is more prevalent because Traccar is recommended to run web servers as root user. It is also more… | |
| Modificada | Media (6.3) | 0.39% | — | Traccar | 2/2/2021 | 17/6/2026 | Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a space, then attacker can lift their privilege to the same… | |
| Modificada | Media (6.5) | 0.85% | — | Traccar | 14/7/2020 | 17/6/2026 | Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only impacts instances with LDAP configuration… | |
| Modificada | Crítica (9.8) | 1.7% | — | Traccar Server | 9/1/2019 | 17/6/2026 | In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks. | |
| Modificada | Crítica (9.8) | 3.8% | — | Traccar Server | 20/12/2018 | 17/6/2026 | Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user.… |