Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.34%—Redqteam WishlistAI16/5/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist allows Retrieve Embedded Sensitive Data.This issue affects Wishlist: from n/a through <= 2.1.0.
AnalizadaMedia (4.8)0.31%—Radiustheme Team - Wordpress Team Members Showcase15/5/202517/6/2026
The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (5.4)0.31%—Wpchurchteam Planning Center Online Giving15/5/202517/6/2026
The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AnalizadaBaja (2.7)0.40%—Spiderteams Applyonline - Application Form Builder AND Manager15/5/202517/6/2026
The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
AnalizadaAlta (7.3)0.18%—Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation13/5/202517/6/2026
A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualization V2312 (All versions < V2312.0010), Teamcenter Visualization V2406 (All versions < V2406.0008), Teamcenter Visualization V2412 (All versions < V2412.0004), Tecnomatix Plant Simulation V2404 (All…
AnalizadaMedia (5.4)0.22%—Alphaefficiencyteam Custom Login AND Registration5/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and Registration: from n/a through 1.0.0.
AplazadaMedia (6.4)0.30%—Wpdarko Team MembersAI1/5/202517/6/2026
The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social Link icons in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaMedia (6.1)63%—Jetbrains Teamcity25/4/202517/6/2026
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
AnalizadaCrítica (9.8)0.55%—Jetbrains Teamcity25/4/202517/6/2026
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
AnalizadaMedia (6.5)1.0%—Jetbrains Teamcity25/4/202517/6/2026
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
AplazadaMedia (5.4)0.27%—Alphaefficiencyteam Custom Login AND RegistrationAI25/4/202517/6/2026
Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0.
AplazadaMedia (6.5)0.27%—Creatorteam Zoho Creator FormsAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5.
AplazadaMedia (5.3)0.33%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI24/4/202517/6/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.6.
AplazadaAlta (7.5)0.70%—Teamzt Smart AgreementsAIPHPAI17/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in teamzt Smart Agreements smart-agreements allows PHP Local File Inclusion.This issue affects Smart Agreements: from n/a through <= 1.0.3.
AplazadaMedia (5.3)0.33%—Magepeopleteam Booking AND Rental ManagerAI17/4/202517/6/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8.
AplazadaAlta (8.8)0.59%—Wpspeedo WPS TeamAI17/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue affects Team Members: from n/a through <= 3.4.4.
AnalizadaAlta (8.8)0.97%—Cisco Webex Teams16/4/202517/6/2026
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when…
AnalizadaMedia (5.9)0.34%—Mattermost ServerMattermost MS Teams16/4/202517/6/2026
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret…
AplazadaAlta (7.5)0.64%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI15/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows PHP Local File Inclusion.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8.
AplazadaCrítica (9.8)0.88%—Magepeopleteam WpbookinglyAI11/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBookingly: from n/a through <= 1.3.0.
AplazadaAlta (8.8)0.48%—Magepeopleteam WpeventlyAI10/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.3.6.
AplazadaMedia (4.9)0.41%—I13websolution Team Circle Image Slider With LightboxAI8/4/202517/6/2026
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (7.1)0.24%—Webdevocean Team BuilderAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team Builder team-display allows Reflected XSS.This issue affects Team Builder: from n/a through <= 1.3.
AplazadaAlta (7.1)0.24%—Shoalsummitsolutions Team RostersAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O'Donnell Team Rosters team-rosters allows Reflected XSS.This issue affects Team Rosters: from n/a through <= 4.7.
AplazadaAlta (8.8)0.66%—Magepeopleteam WP TravellyAIMagepeopleteam Tour Booking ManagerAI1/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n/a through <= 1.8.7.
Orbitaley — Vulnerabilidades