Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.26% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots | |
| Analizada | Alta (8.8) | 0.16% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint | |
| Analizada | Alta (7.5) | 0.18% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms | |
| Analizada | Media (4.8) | 0.79% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page | |
| Analizada | Media (4.3) | 0.22% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration | |
| Analizada | Media (4.3) | 0.22% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | |
| Analizada | Crítica (9.4) | 0.29% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | |
| Analizada | Crítica (9.8) | 0.18% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | |
| Analizada | Alta (7.5) | 0.13% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | |
| Analizada | Alta (8.8) | 0.16% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | |
| Aplazada | Crítica (9.8) | 0.55% | — | Guru Team Site Chat ON TelegramAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4. | |
| Aplazada | Alta (8.8) | 0.58% | — | Beeteam368 ExtensionsAI | 12/7/2025 | 17/6/2026 | The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() function in all versions up to, and including, 2.3.5. This makes it possible for authenticated attackers with Subscriber-level access or higher to upload… | |
| Analizada | Alta (7) | 0.19% | — | Microsoft Teams | 8/7/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. | |
| Analizada | Baja (3.1) | 0.43% | — | Microsoft Teams | 8/7/2025 | 17/6/2026 | Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.6) | 1.0% | — | Teamt5 Threatsonar Anti-ransomwareAI | 7/7/2025 | 17/6/2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and execute them on the server, thereby gaining administrative access to the remote host. | |
| Aplazada | Alta (7.1) | 0.26% | — | Cmoreira Team ShowcaseAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Team Showcase team-showcase-cm allows DOM-Based XSS.This issue affects Team Showcase: from n/a through < 25.05.13. | |
| Analizada | Alta (8.8) | 0.74% | — | Beeteam368 Vidmov | 28/6/2025 | 17/6/2026 | The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally… | |
| Analizada | Alta (8.8) | 0.74% | — | Beeteam368 Vidmov | 28/6/2025 | 17/6/2026 | The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_live_fn() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally… | |
| Aplazada | Media (6.5) | 0.23% | — | Theme-junkie Team ContentAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Junkie Theme Junkie Team Content theme-junkie-team-content allows DOM-Based XSS.This issue affects Theme Junkie Team Content: from n/a through <= 0.1.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Omnipressteam OmnipressAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows DOM-Based XSS.This issue affects Omnipress: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7) | 0.17% | — | Teamviewer RemoteAITeamviewer TensorAI | 24/6/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only… | |
| Analizada | Media (4.8) | 1.2% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible | |
| Analizada | Media (4.3) | 0.36% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions | |
| Analizada | Media (4.8) | 37% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible | |
| Analizada | Media (5.4) | 38% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible |