Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Traccar MEDIUM 5.4
CVE-2026-27693

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality…

Fix: 6.13.0+
Fix from $1,600 2026-05-05
Traccar MEDIUM 5.4
CVE-2026-27694

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates ins…

Fix: 6.13.0+
Fix from $1,600 2026-05-05
Traccar MEDIUM 6.5
CVE-2026-27644

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including us…

Fix: 6.13.0+
Fix from $1,600 2026-05-05
Traccar HIGH 8.7
CVE-2026-25649

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 …

Fix: after 6.11.1
Fix from $1,950 2026-02-23
Traccar HIGH 8.7
CVE-2026-25648

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary Java…

No fix yet
Fix from $1,950 2026-02-23
Traccar MEDIUM 6.5
CVE-2026-23521

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or ed…

Fix: after 6.11.1
Fix from $1,600 2026-02-23
Traccar MEDIUM 6.5
CVE-2025-68930

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in …

Fix: after 6.11.1
Fix from $1,600 2026-02-23
Traccar CRITICAL 9.8
CVE-2024-7746

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue a…

Fix: after 6.0
Fix from $2,300 2024-08-13
Traccar CRITICAL 9.6
CVE-2024-31214EPSS 18%

Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload…

Fix: after 5.12
Fix from $2,300 2024-04-10
Traccar CRITICAL 9.8
CVE-2023-50729

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows…

Fix: 5.11+
Fix from $2,300 2024-01-15
Traccar MEDIUM 6.3
CVE-2021-21292

Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows ve…

Fix: 4.12+
Fix from $1,600 2021-02-02
Traccar MEDIUM 6.5
CVE-2020-5246

Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By …

Fix: 4.9+
Fix from $1,600 2020-07-14
Server CRITICAL 9.8
CVE-2019-5748

In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.

Patch available
Fix from $2,300 2019-01-09
Server CRITICAL 9.8
CVE-2018-1000881

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in Computed…

Fix: after 4.0
Fix from $2,300 2018-12-20