Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.63% | — | Teampasswordmanager Team Password ManagerAI | 1/9/2026 | 23/9/2026 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. | |
| Aplazada | Alta (8.8) | 2.0% | — | Teamviewer Full ClientAITeamviewer HostAI | 26/8/2026 | 1/9/2026 | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking… | |
| Aplazada | Alta (7.5) | 0.27% | — | Teamviewer DesktopAI | 26/8/2026 | 1/9/2026 | Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to… | |
| Aplazada | Alta (7.1) | 0.44% | — | M2team NanazipAI | 20/8/2026 | 18/9/2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe even though… | |
| Aplazada | Baja (2) | 0.32% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.roles array or the runtime usersMap cache. If a permission configuration… | |
| Aplazada | Crítica (9.2) | 0.69% | — | Frangoteam FuxaAINodered Node-redAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and… | |
| Aplazada | Media (6.9) | 0.54% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface, and device-tag metadata without… | |
| Aplazada | Media (6) | 0.46% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an outbound HTTP or HTTPS request and… | |
| Aplazada | Alta (7.5) | 0.52% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups is zero, and POST /api/heartbeat in server/api/index.js re-signs inbound JWT… | |
| Aplazada | Media (6.3) | 0.43% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. An authenticated non-admin operator can create or alter deviceActions… | |
| Aplazada | Media (5.3) | 0.64% | — | Frangoteam FuxaAITdengineAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag… | |
| Aplazada | Alta (8.2) | 0.59% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote unauthenticated… | |
| Aplazada | Media (5.5) | 0.46% | — | Frangoteam FuxaAI | 12/8/2026 | 16/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Teams | 11/8/2026 | 16/8/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.94% | — | Microsoft Teams | 11/8/2026 | 14/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.6) | 0.61% | — | Microsoft Teams | 11/8/2026 | 16/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Alta (7.5) | 0.63% | — | Frangoteam FuxaAI | 10/8/2026 | 28/8/2026 | A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) call… | |
| Aplazada | Alta (8.8) | 0.46% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability… | |
| Aplazada | Media (5.3) | 0.44% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528… | |
| Aplazada | Media (5.3) | 0.45% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in… | |
| Aplazada | Media (5.3) | 0.46% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks,… | |
| Aplazada | Media (5.3) | 0.46% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or… | |
| Aplazada | Crítica (9.2) | 0.71% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a… | |
| Aplazada | Crítica (9.5) | 0.66% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting… | |
| Aplazada | Crítica (9.5) | 0.64% | — | Tobit Laboratories AG TeamdavidAI | 7/8/2026 | 7/9/2026 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service.… |