Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.26%—Oneteamsoftware Radio Buttons AND Swatches FOR WoocommerceAI31/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oneteamsoftware Radio Buttons and Swatches for WooCommerce variations-radio-buttons-for-woocommerce allows Reflected XSS.This issue affects Radio Buttons and Swatches for WooCommerce: from n/a through <= 1.1.20.
AplazadaMedia (5.8)0.33%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI31/1/202517/6/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.1.
ModificadaMedia (6.1)0.33%—Shoalsummitsolutions Team Rosters30/1/202517/6/2026
The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute…
AplazadaAlta (7.8)0.56%—TeamviewerAI28/1/202517/6/2026
Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on a Windows system to elevate privileges via argument injection.
ModificadaAlta (8.8)0.50%—Ninjateam Gdpr Ccpa Compliance & Cookie Consent Banner24/1/202517/6/2026
Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.1.
AplazadaAlta (7.1)0.30%—Falcontheme Team WP Block PackAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FalconTheme Team WP Block Pack wp-block-pack allows Reflected XSS.This issue affects WP Block Pack: from n/a through <= 1.1.6.
AplazadaAlta (7.5)0.66%—Team 118group AgentAI22/1/202517/6/2026
Missing Authorization vulnerability in 118group Team 118GROUP Agent team-118group-agent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team 118GROUP Agent: from n/a through <= 1.6.0.
AnalizadaMedia (6.5)0.31%—Jetbrains Teamcity21/1/202517/6/2026
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
AnalizadaMedia (4.3)0.27%—Jetbrains Teamcity21/1/202517/6/2026
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
AnalizadaMedia (6.1)2.8%—Jetbrains Teamcity21/1/202517/6/2026
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
AplazadaMedia (5.3)0.35%—Magepeopleteam WptravellyAI15/1/202517/6/2026
Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through <= 1.8.5.
AplazadaAlta (7.1)0.26%—Saleswonder Team Wp2leadsAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.2.
AplazadaMedia (4.3)0.19%—Matomoteam MatomoAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in matomoteam Matomo Analytics matomo allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through <= 5.1.1.
AnalizadaAlta (8.1)0.47%—Teampass30/12/202417/6/2026
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
AnalizadaMedia (5.3)0.31%—Teampass30/12/202417/6/2026
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
AnalizadaMedia (4.3)0.34%—Teampass30/12/202417/6/2026
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.
AplazadaMedia (5.3)0.32%—Marp-team Marp-coreAI26/12/202417/6/2026
@marp-team/marp-core is the core for Marp, which is the ecosystem to write your presentation with plain Markdown. Marp Core from v3.0.2 to v3.9.0 and v4.0.0, are vulnerable to cross-site scripting (XSS) due to improper neutralization of HTML sanitization. Marp Core v3.9.1 and v4.0.1 have been patched to fix that. If…
AplazadaMedia (6.4)0.28%—Ninjateam Chat FOR TelegramAI24/12/202417/6/2026
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.8)0.36%—DigiteamAI20/12/202417/6/2026
Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.
AnalizadaAlta (7.1)0.24%—Jetbrains Teamcity20/12/202417/6/2026
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
AnalizadaMedia (5.4)0.80%—Jetbrains Teamcity20/12/202417/6/2026
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
AnalizadaMedia (4.9)0.30%—Jetbrains Teamcity20/12/202417/6/2026
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
AnalizadaMedia (6.5)0.31%—Jetbrains Teamcity20/12/202417/6/2026
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
AnalizadaMedia (5.4)0.80%—Jetbrains Teamcity20/12/202417/6/2026
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
AnalizadaAlta (8.8)0.31%—Jetbrains Teamcity20/12/202417/6/2026
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
Orbitaley — Vulnerabilidades