Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.50%—Yeti-platform YetiAI16/9/202623/9/2026
Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
AnalizadaAlta (7.5)0.43%—Yeti-platform Yeti8/5/202617/6/2026
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
AnalizadaAlta (7.3)3.9%—Yeti-platform Yeti8/5/202617/6/2026
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
AplazadaMedia (6.9)0.29%—Yetishare File Hosting ScriptAI23/1/202617/6/2026
YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:///…
ModificadaAlta (7.5)0.78%—Yeti-platform Yeti10/9/202417/6/2026
Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode normalization with a compatibility form NFKD. Under Windows, such normalization is costly in resources and may lead to denial of service with attacks…
ModificadaMedia (6.5)1.0%—Yetiforce Customer Relationship Management16/2/202417/6/2026
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
ModificadaMedia (5.4)0.70%—Yetiforce Customer Relationship Management6/10/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (5.4)0.63%—Yetiforce Customer Relationship Management20/9/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (5.4)0.63%—Yetiforce Customer Relationship Management20/9/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (5.4)0.63%—Yetiforce Customer Relationship Management20/9/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (5.4)0.78%—Yetiforce Customer Relationship Management20/9/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
ModificadaMedia (5.4)0.83%—Yetiforce Customer Relationship Management23/8/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (5.4)0.87%—Yetiforce Customer Relationship Management22/8/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (5.4)0.49%—Yetiforce Customer Relationship Management22/8/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (4.8)0.47%—Yetiforce Customer Relationship Management21/8/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ModificadaMedia (6.1)0.76%—Yetiforce Customer Relationship Management5/5/202217/6/2026
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
ModificadaAlta (8)0.53%—Yetiforce Customer Relationship Management24/1/202217/6/2026
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
ModificadaMedia (6.1)0.76%—Yetiforce Customer Relationship Management16/12/202117/6/2026
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.3)0.71%—Yetiforce Customer Relationship Management15/12/202117/6/2026
yetiforcecrm is vulnerable to Business Logic Errors
ModificadaMedia (5.4)0.46%—Yetiforce Customer Relationship Management15/12/202117/6/2026
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.3)0.62%—Yetiforce Customer Relationship Management15/12/202117/6/2026
yetiforcecrm is vulnerable to Business Logic Errors
ModificadaMedia (6.1)0.78%—Yetiforce Customer Relationship Management14/12/202117/6/2026
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.3)0.38%—Yetiforce Customer Relationship Management11/12/202117/6/2026
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaCrítica (9.8)1.6%—Mfscripts Yetishare10/2/202017/6/2026
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
ModificadaAlta (7.5)0.90%—Mfscripts Yetishare10/2/202017/6/2026
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.