Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle Yard Management | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Yard Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks… | |
| Aplazada | Media (5.3) | 0.40% | — | Yardoc YardAI | 19/6/2026 | 23/6/2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root… | |
| Analizada | Media (6.9) | 0.52% | — | Yardoc Yard | 8/5/2026 | 17/6/2026 | YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been… | |
| Analizada | Media (5.4) | 0.15% | — | 10ij Dockyard | 9/4/2026 | 8/7/2026 | Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or… | |
| Analizada | Crítica (9.8) | 0.58% | — | Kaleris Yard Management Solutions | 6/4/2026 | 17/6/2026 | An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources. | |
| Analizada | Media (4.3) | 0.29% | — | Kaleris Yard Management Solutions | 6/4/2026 | 17/6/2026 | Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources. | |
| Aplazada | Media (6.5) | 0.38% | — | Michael Simpson Community Yard SaleAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale community-yard-sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through <= 1.1.11. | |
| Analizada | Alta (7.3) | 0.26% | — | Tramyardg Autoexpress | 19/4/2024 | 17/6/2026 | SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter. | |
| Analizada | Media (6.1) | 0.57% | — | Tramyardg Autoexpress | 21/3/2024 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php. | |
| Analizada | Crítica (9.8) | 1.3% | — | Tramyardg Autoexpress | 21/3/2024 | 17/6/2026 | An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php. | |
| Analizada | Crítica (9.8) | 1.0% | — | Tramyardg Autoexpress | 21/3/2024 | 17/6/2026 | A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php. | |
| Analizada | Media (6.1) | 1.1% | — | Yardoc YardFedoraproject FedoraDebian Linux | 28/2/2024 | 17/6/2026 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36. | |
| Modificada | Media (5.4) | 0.47% | — | Yellowyard Yellow Yard Searchbar | 16/8/2023 | 17/6/2026 | The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.49% | — | Yellowyard Yellow Yard Searchbar | 8/2/2023 | 17/6/2026 | The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting | |
| Modificada | Alta (7.5) | 0.73% | — | Lastyard Last Yard | 1/2/2023 | 17/6/2026 | Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS). | |
| Modificada | Media (5.3) | 0.39% | — | Lastyard Last Yard | 1/2/2023 | 17/6/2026 | In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic. | |
| Modificada | Crítica (9.8) | 0.61% | — | Lastyard Last Yard | 1/2/2023 | 17/6/2026 | Last Yard 22.09.8-1 does not enforce HSTS headers | |
| Modificada | Crítica (9.8) | 2.5% | — | Talkyard | 3/1/2022 | 17/6/2026 | In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain… | |
| Modificada | Alta (8.8) | 1.3% | — | Talkyard | 11/11/2021 | 17/6/2026 | In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated… | |
| Modificada | Alta (7.5) | 2.3% | — | Yardoc Yard | 29/7/2019 | 17/6/2026 | yard before 0.9.20 allows path traversal. | |
| Modificada | Alta (7.5) | 2.9% | — | Yardoc Yard | 28/11/2017 | 17/6/2026 | lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. | |
| Modificada | Media (5.4) | 0.27% | — | Appsgeyser Backyard Wrestling | 21/10/2014 | 17/6/2026 | The Backyard Wrestling (aka com.wBackyardWrestling) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Highlighterstudio Vineyard ALL IN | 20/10/2014 | 17/6/2026 | The Vineyard All In (aka com.wVineyardAllIn) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 3.7% | — | Yard Radius Project Yard Radius | 9/8/2013 | 16/6/2026 | Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function… |