Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Redqteam WishlistAI | 16/5/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist allows Retrieve Embedded Sensitive Data.This issue affects Wishlist: from n/a through <= 2.1.0. | |
| Analizada | Media (4.8) | 0.31% | — | Radiustheme Team - Wordpress Team Members Showcase | 15/5/2025 | 17/6/2026 | The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.31% | — | Wpchurchteam Planning Center Online Giving | 15/5/2025 | 17/6/2026 | The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Baja (2.7) | 0.40% | — | Spiderteams Applyonline - Application Form Builder AND Manager | 15/5/2025 | 17/6/2026 | The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain | |
| Analizada | Alta (7.3) | 0.18% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualization V2312 (All versions < V2312.0010), Teamcenter Visualization V2406 (All versions < V2406.0008), Teamcenter Visualization V2412 (All versions < V2412.0004), Tecnomatix Plant Simulation V2404 (All… | |
| Analizada | Media (5.4) | 0.22% | — | Alphaefficiencyteam Custom Login AND Registration | 5/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and Registration: from n/a through 1.0.0. | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdarko Team MembersAI | 1/5/2025 | 17/6/2026 | The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social Link icons in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (6.1) | 63% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab | |
| Analizada | Crítica (9.8) | 0.55% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible | |
| Analizada | Media (6.5) | 1.0% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | |
| Aplazada | Media (5.4) | 0.27% | — | Alphaefficiencyteam Custom Login AND RegistrationAI | 25/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Creatorteam Zoho Creator FormsAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5. | |
| Aplazada | Media (5.3) | 0.33% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 24/4/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.6. | |
| Aplazada | Alta (7.5) | 0.70% | — | Teamzt Smart AgreementsAIPHPAI | 17/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in teamzt Smart Agreements smart-agreements allows PHP Local File Inclusion.This issue affects Smart Agreements: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.33% | — | Magepeopleteam Booking AND Rental ManagerAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8. | |
| Aplazada | Alta (8.8) | 0.59% | — | Wpspeedo WPS TeamAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue affects Team Members: from n/a through <= 3.4.4. | |
| Analizada | Alta (8.8) | 0.97% | — | Cisco Webex Teams | 16/4/2025 | 17/6/2026 | A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when… | |
| Analizada | Media (5.9) | 0.34% | — | Mattermost ServerMattermost MS Teams | 16/4/2025 | 17/6/2026 | Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret… | |
| Aplazada | Alta (7.5) | 0.64% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 15/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows PHP Local File Inclusion.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8. | |
| Aplazada | Crítica (9.8) | 0.88% | — | Magepeopleteam WpbookinglyAI | 11/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBookingly: from n/a through <= 1.3.0. | |
| Aplazada | Alta (8.8) | 0.48% | — | Magepeopleteam WpeventlyAI | 10/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.3.6. | |
| Aplazada | Media (4.9) | 0.41% | — | I13websolution Team Circle Image Slider With LightboxAI | 8/4/2025 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.24% | — | Webdevocean Team BuilderAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team Builder team-display allows Reflected XSS.This issue affects Team Builder: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.24% | — | Shoalsummitsolutions Team RostersAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O'Donnell Team Rosters team-rosters allows Reflected XSS.This issue affects Team Rosters: from n/a through <= 4.7. | |
| Aplazada | Alta (8.8) | 0.66% | — | Magepeopleteam WP TravellyAIMagepeopleteam Tour Booking ManagerAI | 1/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n/a through <= 1.8.7. |