Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 11/3/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the… | |
| Analizada | Media (4.8) | 0.16% | — | Hcltech Digital Experience | 20/2/2026 | 17/6/2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit. | |
| Analizada | Media (6.8) | 0.77% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected… | |
| Analizada | Media (6.5) | 0.66% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical… | |
| Analizada | Alta (7.5) | 0.37% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR… | |
| Analizada | Alta (8.1) | 0.21% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be… | |
| Analizada | Media (6.5) | 0.34% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted… | |
| Analizada | Media (6.5) | 0.16% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log… | |
| Analizada | Media (6.5) | 0.18% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content… | |
| Analizada | Media (6.5) | 0.13% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information. | |
| Analizada | Alta (7.1) | 0.23% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the… | |
| Analizada | Alta (7.7) | 0.17% | — | Kentico Xperience | 5/1/2026 | 7/10/2026 | Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context. | |
| Analizada | Alta (8.2) | 0.52% | — | Microsoft Office Out-of-box Experience | 18/12/2025 | 1/10/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.1) | 0.17% | — | Kentico Xperience | 18/12/2025 | 17/6/2026 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder. | |
| Modificada | Media (5.1) | 0.17% | — | Kentico Xperience | 18/12/2025 | 17/6/2026 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers. | |
| Modificada | Media (5.1) | 0.17% | — | Kentico Xperience | 18/12/2025 | 17/6/2026 | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers. | |
| Analizada | Media (6.9) | 0.27% | — | Kentico Xperience | 18/12/2025 | 17/6/2026 | An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal network details. |