Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.40% | — | Team Atomchat AtomchatAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Team AtomChat AtomChat atomchat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through <= 1.1.7. | |
| Aplazada | Media (6.5) | 0.36% | — | Draftpress Team Follow US BadgesAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DraftPress Team Follow Us Badges wpsite-follow-us-badges allows Stored XSS.This issue affects Follow Us Badges: from n/a through <= 3.1.11. | |
| Aplazada | Media (6.5) | 0.36% | — | Sultan Nasir Uddin Team Members FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder team-members-for-elementor allows Stored XSS.This issue affects Team Members for Elementor Page Builder: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.31% | — | Saleswonder Team Wp2leadsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.5. | |
| Aplazada | Media (4.3) | 0.37% | — | Wpbean OUR Team MembersAI | 1/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPBean Our Team Members our-team-members.This issue affects Our Team Members: from n/a through <= 2.2. | |
| Aplazada | Media (6.5) | 0.26% | — | Team Atomchat AtomchatAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team AtomChat AtomChat atomchat allows Stored XSS.This issue affects AtomChat: from n/a through <= 1.1.8. | |
| Aplazada | Alta (7.1) | 0.13% | — | Strategy11 Team Terms OF USEAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Terms of Use terms-of-use-2 allows Stored XSS.This issue affects Terms of Use: from n/a through <= 2.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Ninjateam Click TO Chat WP Support ALL IN ONE Floating WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4. | |
| Analizada | Alta (7.5) | 0.36% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page | |
| Analizada | Media (6.1) | 28% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page | |
| Analizada | Media (6.5) | 1.0% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log | |
| Aplazada | Alta (7.5) | 0.81% | — | Magepeopleteam WpeventlyAI | 27/3/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP Local File Inclusion.This issue affects WpEvently: from n/a through <= 4.2.9. | |
| Aplazada | Alta (8.8) | 0.67% | — | Magepeopleteam WptravellyAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly tour-booking-manager allows PHP Local File Inclusion.This issue affects WpTravelly: from n/a through <= 1.8.7. | |
| Aplazada | Media (5.3) | 0.37% | — | Magepeopleteam WP EventlyAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.2.9. | |
| Aplazada | Alta (7.6) | 0.58% | — | Moreconvert Team MC Woocommerce WishlistAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert allows SQL Injection.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.8.9. | |
| Aplazada | Alta (7.5) | 1.1% | — | Maidul Team ManagerAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maidul Team Manager wp-team-manager allows PHP Local File Inclusion.This issue affects Team Manager: from n/a through <= 2.1.23. | |
| Aplazada | Media (5.3) | 0.49% | — | Magepeopleteam Taxi Booking Manager FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.2.1. | |
| Analizada | Media (6.1) | 0.44% | 💥 PoC | Inflectra Spirateam | 20/3/2025 | 17/6/2026 | Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing. | |
| Analizada | Crítica (9.8) | 0.84% | 💥 PoC | Inflectra Spirateam | 20/3/2025 | 17/6/2026 | Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information. | |
| Aplazada | Alta (8.8) | 0.46% | — | Magepeopleteam Booking AND Rental ManagerAI | 15/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.2.6. | |
| Analizada | Media (6.5) | 0.28% | — | Omnipressteam Omnipress | 14/3/2025 | 17/6/2026 | The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from… | |
| Analizada | Alta (7.3) | 0.16% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All… | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All… | |
| Analizada | Alta (7.3) | 0.16% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All… | |
| Analizada | Alta (7.3) | 0.16% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions < V2406.0007), Teamcenter Visualization V2412 (All versions < V2412.0002), Tecnomatix Plant Simulation V2302 (All… |