Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.97%—Jetbrains Teamcity23/6/202517/6/2026
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
AplazadaMedia (5.9)0.20%—Ninjateam File Manager PROAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team File Manager Pro filester allows Stored XSS.This issue affects File Manager Pro: from n/a through <= 1.8.8.
AplazadaAlta (7.1)0.34%—Saleswonder Team Wp2leadsAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.5.0.
AplazadaAlta (7.6)0.34%—Webdevocean Team BuilderAI9/6/202517/6/2026
Missing Authorization vulnerability in looks_awesome Team Builder a-team-showcase allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Builder: from n/a through <= 1.5.7.
AplazadaAlta (7.1)0.28%—Redqteam WishlistAI9/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Wishlist wishlist allows Reflected XSS.This issue affects Wishlist: from n/a through <= 2.1.0.
AplazadaMedia (6.5)0.25%—HT Plugins HT Team MemberAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Team Member ht-team-member allows Stored XSS.This issue affects HT Team Member: from n/a through <= 1.1.7.
AplazadaMedia (4.3)0.33%—Cmoreira Team-showcase-cmAI6/6/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase team-showcase-cm allows Code Injection.This issue affects Team Showcase: from n/a through < 25.05.13.
AplazadaMedia (4.3)0.28%—Cmoreira Team ShowcaseAI6/6/202517/6/2026
Missing Authorization vulnerability in cmoreira Team Showcase team-showcase-cm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Showcase: from n/a through < 25.05.13.
AplazadaMedia (6.5)0.28%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI2/6/202517/6/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.8.
AnalizadaMedia (5.4)0.27%—Ninjateam Chat FOR Telegram30/5/202517/6/2026
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AnalizadaMedia (6.3)0.56%—Project Team Tmall Demo25/5/202517/6/2026
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of…
AnalizadaMedia (4.8)0.34%—Project Team Tmall Demo24/5/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of the file /tmall/admin/ of the component Product Details Page. The manipulation of the argument Product Name/Product Title leads to cross site scripting. The attack…
AnalizadaMedia (5.1)0.33%—Project Team Tmall Demo24/5/202517/6/2026
A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy Item Page. The manipulation of the argument Detailed Address leads to cross site scripting. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.43%—Project Team Tmall Demo24/5/202517/6/2026
A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is…
AnalizadaMedia (5.3)0.31%—Project Team Tmall Demo24/5/202517/6/2026
A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmall/admin/account/logout. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (5.1)0.55%—Project Team Tmall Demo24/5/202517/6/2026
A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage of the file tmall/admin/uploadCategoryImage. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (5.1)0.47%—Project Team Tmall Demo24/5/202517/6/2026
A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file tmall/admin/uploadProductImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been…
AplazadaAlta (8.4)0.20%—Valve SteamAI21/5/202517/6/2026
An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.
AnalizadaMedia (6.1)0.26%—Jetbrains Teamcity20/5/202517/6/2026
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
AnalizadaMedia (5.4)0.73%—Jetbrains Teamcity20/5/202517/6/2026
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
AnalizadaMedia (5.4)0.73%—Jetbrains Teamcity20/5/202517/6/2026
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
AnalizadaMedia (5.4)2.7%—Jetbrains Teamcity20/5/202517/6/2026
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
AplazadaMedia (4.3)0.25%—Ninjateam Gdpr Ccpa Compliance SupportAI19/5/202517/6/2026
Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.3.
AplazadaAlta (8.6)0.47%—Teamt5 Threatsonar Anti-ransomwareAI19/5/202517/6/2026
The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API.
AplazadaMedia (4.3)0.28%—Redqteam WishlistAI16/5/202517/6/2026
Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wishlist: from n/a through <= 2.1.0.