Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.26% | — | Radiustheme Tlp-teamAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.6. | |
| Aplazada | Alta (7.5) | 0.54% | — | Immonex Kickstart TeamAIPHPAI | 22/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart Team immonex-kickstart-team allows PHP Local File Inclusion.This issue affects immonex Kickstart Team: from n/a through <= 1.6.9. | |
| Aplazada | Media (5.3) | 0.30% | — | Dynamicweblab Wp-team-managerAI | 22/9/2025 | 5/10/2026 | Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.8. | |
| Analizada | Alta (7.7) | 0.83% | — | Jetbrains Teamcity | 17/9/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows | |
| Analizada | Media (5.5) | 14% | — | Jetbrains Teamcity | 17/9/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | |
| Analizada | Media (4.2) | 0.42% | — | Jetbrains Teamcity | 17/9/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition | |
| Analizada | Media (5.4) | 0.20% | — | Zeon Teampel | 15/9/2025 | 17/6/2026 | Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx. | |
| Aplazada | Media (6.5) | 0.22% | — | Ibnul H Custom Team ManagerAI | 5/9/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ibnul H. Custom Team Manager custom-team-manager allows Stored XSS.This issue affects Custom Team Manager: from n/a through <= 2.4.2. | |
| Aplazada | Media (4.3) | 0.30% | — | Aa-team PRO Bulk WatermarkAI | 30/8/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through 2.0. | |
| Aplazada | Alta (8.1) | 0.33% | — | Emarketdesign Employee Directory Staff Listing Team DirectoryAI | 28/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory allows Object Injection.This issue affects Employee Directory – Staff Listing & Team Directory Plugin for WordPress: from n/a through <= 4.5.5. | |
| Aplazada | Alta (8.8) | 0.37% | — | Magepeopleteam WP EventlyAI | 28/8/2025 | 25/9/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.4.8. | |
| Aplazada | Media (6.1) | 0.10% | — | TeamviewerAI | 26/8/2025 | 17/6/2026 | Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows allows a local non-admin user to create arbitrary files with SYSTEM privileges, potentially leading to a denial-of-service condition, via symbolic link manipulation during directory verification. | |
| Analizada | Media (6.5) | 0.80% | — | Jetbrains Teamcity | 20/8/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files | |
| Analizada | Baja (3.8) | 0.28% | — | Jetbrains Teamcity | 20/8/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content | |
| Analizada | Media (6.3) | 0.12% | — | Jetbrains Teamcity | 20/8/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership | |
| Aplazada | Crítica (9.8) | 0.56% | — | Magepeopleteam Taxi Booking Manager FOR WoocommerceAI | 20/8/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.3.0. | |
| Aplazada | Alta (7.5) | 0.57% | — | Saleswonder Team CF7 WOW StylerAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler allows PHP Local File Inclusion.This issue affects CF7 WOW Styler: from n/a through <= 1.7.2. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Allskyteam AllskyAI | 19/8/2025 | 17/6/2026 | A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php. | |
| Aplazada | Media (4.3) | 0.25% | — | Magepeopleteam WpeventlyAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.4.6. | |
| Aplazada | Alta (7.1) | 0.23% | — | Redqteam Alike - Wordpress Custom Post ComparisonAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Alike - WordPress Custom Post Comparison alike allows Reflected XSS.This issue affects Alike - WordPress Custom Post Comparison: from n/a through <= 3.0.1. | |
| Aplazada | Crítica (10) | 0.52% | — | Beeteam368 ExtensionsAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensions beeteam368-extensions allows PHP Local File Inclusion.This issue affects BeeTeam368 Extensions: from n/a through <= 1.9.4. | |
| Aplazada | Alta (8.1) | 0.65% | — | Beeteam368 VidmovAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidMov vidmov allows PHP Local File Inclusion.This issue affects VidMov: from n/a through <= 1.9.4. | |
| Analizada | Alta (7.5) | 0.81% | 💥 PoC | Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+1 | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.5) | 0.39% | — | Ninjateam FilebirdAI | 6/8/2025 | 17/6/2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Analizada | Media (5.5) | 0.26% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command |