Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.43%—Oracle Yard Management18/8/202628/8/2026
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks…
AnalizadaAlta (8.8)0.43%—Oracle Yard Management21/7/202628/7/2026
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks…
AplazadaMedia (5.3)0.40%—Yardoc YardAI19/6/202623/6/2026
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root…
AnalizadaMedia (6.9)0.52%—Yardoc Yard8/5/202617/6/2026
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been…
AnalizadaMedia (5.4)0.15%—10ij Dockyard9/4/20268/7/2026
Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or…
AnalizadaCrítica (9.8)0.58%—Kaleris Yard Management Solutions6/4/202617/6/2026
An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources.
AnalizadaMedia (4.3)0.29%—Kaleris Yard Management Solutions6/4/202617/6/2026
Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources.
AplazadaMedia (6.5)0.38%—Michael Simpson Community Yard SaleAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale community-yard-sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through <= 1.1.11.
AnalizadaAlta (7.3)0.26%—Tramyardg Autoexpress19/4/202417/6/2026
SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter.
AnalizadaMedia (6.1)0.57%—Tramyardg Autoexpress21/3/202417/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.
AnalizadaCrítica (9.8)1.3%—Tramyardg Autoexpress21/3/202417/6/2026
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.
AnalizadaCrítica (9.8)1.0%—Tramyardg Autoexpress21/3/202417/6/2026
A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.
AnalizadaMedia (6.1)1.1%—Yardoc YardFedoraproject FedoraDebian Linux28/2/202417/6/2026
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
ModificadaMedia (5.4)0.47%—Yellowyard Yellow Yard Searchbar16/8/202317/6/2026
The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.49%—Yellowyard Yellow Yard Searchbar8/2/202317/6/2026
The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting
ModificadaAlta (7.5)0.73%—Lastyard Last Yard1/2/202317/6/2026
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
ModificadaMedia (5.3)0.39%—Lastyard Last Yard1/2/202317/6/2026
In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.
ModificadaCrítica (9.8)0.61%—Lastyard Last Yard1/2/202317/6/2026
Last Yard 22.09.8-1 does not enforce HSTS headers
ModificadaCrítica (9.8)2.5%—Talkyard3/1/202217/6/2026
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain…
ModificadaAlta (8.8)1.3%—Talkyard11/11/202117/6/2026
In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated…
ModificadaAlta (7.5)2.3%—Yardoc Yard29/7/201917/6/2026
yard before 0.9.20 allows path traversal.
ModificadaAlta (7.5)2.9%—Yardoc Yard28/11/201717/6/2026
lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
ModificadaMedia (5.4)0.27%—Appsgeyser Backyard Wrestling21/10/201417/6/2026
The Backyard Wrestling (aka com.wBackyardWrestling) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Highlighterstudio Vineyard ALL IN20/10/201417/6/2026
The Vineyard All In (aka com.wVineyardAllIn) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)3.7%—Yard Radius Project Yard Radius9/8/201316/6/2026
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function…