Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.29% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | |
| Analizada | Media (5.3) | 0.29% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | |
| Analizada | Media (4.3) | 0.29% | 💥 PoC | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | |
| Analizada | Media (4.3) | 0.35% | — | Ninjateam Filester | 19/12/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Crítica (9.8) | 0.81% | — | Microsoft Teams | 18/12/2024 | 17/6/2026 | A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then… | |
| Analizada | Crítica (9.8) | 0.80% | — | Microsoft Teams | 18/12/2024 | 17/6/2026 | A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger… | |
| Analizada | Crítica (9.8) | 0.91% | — | Microsoft Teams | 18/12/2024 | 17/6/2026 | A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start… | |
| Aplazada | Crítica (9.3) | 1.8% | 💥 PoC | Richteam Rich-web-share-buttonAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2. | |
| Aplazada | Media (4.3) | 0.69% | — | Team Plugins360 Automatic Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3. | |
| Aplazada | Media (6.5) | 0.64% | — | Ovic Team Ovic Product BundleAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Ovic Team Ovic Product Bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ovic Product Bundle: from n/a through 1.1.2. | |
| Aplazada | Media (4.3) | 0.28% | — | Ninjateam NotibarAI | 11/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team Notibar notibar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notibar: from n/a through <= 2.1.4. | |
| Aplazada | Alta (7.1) | 0.15% | — | Teamviewer Patch AND Asset ManagementAI | 11/12/2024 | 17/6/2026 | Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. TeamViewer Patch & Asset Management is part of TeamViewer Remote Management. | |
| Analizada | Alta (7.3) | 0.18% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions < V2312.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404… | |
| Analizada | Alta (7.3) | 0.18% | — | Siemens Teamcenter VisualizationSiemens Tecnomatix Plant Simulation | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions < V2312.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404… | |
| Aplazada | Media (4.3) | 0.44% | — | Wpmart Team MemberAI | 9/12/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpmart Team Member team-showcase-supreme.This issue affects Team Member: from n/a through <= 7.4. | |
| Modificada | Media (6.5) | 0.65% | — | Ninjateam Filebird | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 5.1.4. | |
| Modificada | Alta (7.2) | 0.36% | — | Ninjateam Filebird | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through <= 6.3.2. | |
| Modificada | Alta (7.2) | 0.98% | — | Ninjateam Filester | 28/11/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the… | |
| Analizada | Alta (8.8) | 1.1% | — | Ninjateam Filester | 28/11/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Shoalsummitsolutions Team RostersAI | 20/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This issue affects Team Rosters: from n/a through <= 4.8.2. | |
| Aplazada | Media (6.5) | 0.32% | — | Luzuk Team LuzukAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in luzuk Themes Luzuk Team luzuk-team allows Stored XSS.This issue affects Luzuk Team: from n/a through <= 0.1.0. | |
| Aplazada | Media (6.5) | 0.24% | — | Offshorent Solutions PVT LTD OS OUR TeamAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS Our Team os-our-team allows Stored XSS.This issue affects OS Our Team: from n/a through <= 1.7. | |
| Analizada | Media (5.4) | 0.82% | — | Cisco Webex Teams | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or… | |
| Analizada | Media (4.3) | 0.46% | — | Ninjateam WP Chat APP | 16/11/2024 | 17/6/2026 | The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all versions up to, and including, 3.6.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the filebird… | |
| Aplazada | Crítica (10) | 0.51% | — | Team Devexhub Devexhub GalleryAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows Upload a Web Shell to a Web Server.This issue affects Devexhub Gallery: from n/a through <= 2.0.1. |