Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.43% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4. | |
| Aplazada | Media (6.5) | 0.32% | — | Saleswonder Team Webinar-ignitionAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04. | |
| Analizada | Baja (1.9) | 0.28% | — | Xiweicheng Teamwork Management System | 17/12/2025 | 17/6/2026 | A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be… | |
| Analizada | Crítica (10) | 1.8% | — | Allskyteam Allsky | 16/12/2025 | 17/6/2026 | A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a malicious payload in the id parameter, an attacker can execute arbitrary commands on the… | |
| Analizada | Media (6.1) | 0.21% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page | |
| Analizada | Media (6.5) | 0.21% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token | |
| Analizada | Media (6.1) | 0.20% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab | |
| Analizada | Media (6.1) | 4.2% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup | |
| Analizada | Baja (2.7) | 0.24% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test | |
| Analizada | Media (4.8) | 0.19% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page | |
| Analizada | Baja (2.7) | 0.21% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration | |
| Aplazada | Alta (7.6) | 0.39% | — | Aioseo Plugin Team Broken Link CheckerAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team Broken Link Checker broken-link-checker-seo allows SQL Injection.This issue affects Broken Link Checker: from n/a through <= 1.2.6. | |
| Aplazada | Media (5.4) | 0.25% | — | Ninjateam Filebird PROAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in NinjaTeam FileBird Pro filebird-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FileBird Pro: from n/a through <= 6.5.1. | |
| Aplazada | Media (4.3) | 0.23% | — | Ninjateam FilebirdAI | 15/12/2025 | 7/10/2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Baja (1.9) | 0.20% | — | Atlaszz AI Photo Team GalleryAI | 15/12/2025 | 7/10/2026 | A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part of the component gallery.photogallery.pictures.vault.album. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been made available to the public and… | |
| Analizada | Alta (7.5) | 0.80% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 path traversal was possible via file upload | |
| Analizada | Media (5.4) | 0.49% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute | |
| Analizada | Media (5.3) | 0.22% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata | |
| Analizada | Baja (3.1) | 0.17% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure | |
| Analizada | Media (6.7) | 0.17% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution,… | |
| Analizada | Media (6.7) | 0.18% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.83% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote… |