Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.50% | — | Yeti-platform YetiAI | 16/9/2026 | 23/9/2026 | Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects. | |
| Analizada | Alta (7.5) | 0.43% | — | Yeti-platform Yeti | 8/5/2026 | 17/6/2026 | yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET). | |
| Analizada | Alta (7.3) | 3.9% | — | Yeti-platform Yeti | 8/5/2026 | 17/6/2026 | A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server. | |
| Aplazada | Media (6.9) | 0.29% | — | Yetishare File Hosting ScriptAI | 23/1/2026 | 17/6/2026 | YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:///… | |
| Modificada | Alta (7.5) | 0.78% | — | Yeti-platform Yeti | 10/9/2024 | 17/6/2026 | Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode normalization with a compatibility form NFKD. Under Windows, such normalization is costly in resources and may lead to denial of service with attacks… | |
| Modificada | Media (6.5) | 1.0% | — | Yetiforce Customer Relationship Management | 16/2/2024 | 17/6/2026 | Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component. | |
| Modificada | Media (5.4) | 0.70% | — | Yetiforce Customer Relationship Management | 6/10/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (5.4) | 0.63% | — | Yetiforce Customer Relationship Management | 20/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (5.4) | 0.63% | — | Yetiforce Customer Relationship Management | 20/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (5.4) | 0.63% | — | Yetiforce Customer Relationship Management | 20/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (5.4) | 0.78% | — | Yetiforce Customer Relationship Management | 20/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3. | |
| Modificada | Media (5.4) | 0.83% | — | Yetiforce Customer Relationship Management | 23/8/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (5.4) | 0.87% | — | Yetiforce Customer Relationship Management | 22/8/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (5.4) | 0.49% | — | Yetiforce Customer Relationship Management | 22/8/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (4.8) | 0.47% | — | Yetiforce Customer Relationship Management | 21/8/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | |
| Modificada | Media (6.1) | 0.76% | — | Yetiforce Customer Relationship Management | 5/5/2022 | 17/6/2026 | Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover. | |
| Modificada | Alta (8) | 0.53% | — | Yetiforce Customer Relationship Management | 24/1/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0. | |
| Modificada | Media (6.1) | 0.76% | — | Yetiforce Customer Relationship Management | 16/12/2021 | 17/6/2026 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.3) | 0.71% | — | Yetiforce Customer Relationship Management | 15/12/2021 | 17/6/2026 | yetiforcecrm is vulnerable to Business Logic Errors | |
| Modificada | Media (5.4) | 0.46% | — | Yetiforce Customer Relationship Management | 15/12/2021 | 17/6/2026 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.3) | 0.62% | — | Yetiforce Customer Relationship Management | 15/12/2021 | 17/6/2026 | yetiforcecrm is vulnerable to Business Logic Errors | |
| Modificada | Media (6.1) | 0.78% | — | Yetiforce Customer Relationship Management | 14/12/2021 | 17/6/2026 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.3) | 0.38% | — | Yetiforce Customer Relationship Management | 11/12/2021 | 17/6/2026 | yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Crítica (9.8) | 1.6% | — | Mfscripts Yetishare | 10/2/2020 | 17/6/2026 | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). | |
| Modificada | Alta (7.5) | 0.90% | — | Mfscripts Yetishare | 10/2/2020 | 17/6/2026 | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password. |