Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.7)0.40%—Spiderteams Applyonline - Application Form Builder AND Manager15/5/202517/6/2026
The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain
AnalizadaAlta (8.8)0.97%—Cisco Webex Teams16/4/202517/6/2026
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when…
AnalizadaMedia (5.9)0.34%—Mattermost ServerMattermost MS Teams16/4/202517/6/2026
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret…
AplazadaAlta (7.1)0.26%—Oneteamsoftware Radio Buttons AND Swatches FOR WoocommerceAI31/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oneteamsoftware Radio Buttons and Swatches for WooCommerce variations-radio-buttons-for-woocommerce allows Reflected XSS.This issue affects Radio Buttons and Swatches for WooCommerce: from n/a through <= 1.1.20.
AnalizadaCrítica (9.8)0.81%—Microsoft Teams18/12/202417/6/2026
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then…
AnalizadaCrítica (9.8)0.80%—Microsoft Teams18/12/202417/6/2026
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger…
AnalizadaCrítica (9.8)0.91%—Microsoft Teams18/12/202417/6/2026
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start…
AnalizadaMedia (5.4)0.82%—Cisco Webex Teams18/11/202417/6/2026
A vulnerability in the web-based interface of Cisco&nbsp;Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or…
AnalizadaMedia (6.5)16%—Microsoft Teams13/8/202417/6/2026
Microsoft Teams for iOS Spoofing Vulnerability
AnalizadaMedia (6.5)0.42%—Cisco Webex Teams17/7/202417/6/2026
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a…
AnalizadaAlta (7.3)0.22%—Cisco Webex Teams17/7/202417/6/2026
A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to insecure transmission of requests to backend services when the app accesses embedded media, such as images. An attacker…
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
AplazadaMedia (6.1)0.57%—Ca17 TeamsacsAI2/4/20249/7/2026
Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.
AnalizadaMedia (5)1.2%—Microsoft Teams12/3/202417/6/2026
Microsoft Teams for Android Information Disclosure Vulnerability
ModificadaMedia (5)0.97%—Microsoft Teams13/2/202410/8/2026
Microsoft Teams for Android Information Disclosure Vulnerability
ModificadaMedia (5.3)0.57%—Jenkins Msteams Webhook Trigger25/10/202317/6/2026
Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
ModificadaMedia (6.1)0.44%—Spiderteams Applyonline - Application Form Builder AND Manager25/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline – Application Form Builder and Manager plugin <= 2.5.2 versions.
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxMozilla Firefox+812/9/202317/6/2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
ModificadaMedia (4.8)0.37%—Spiderteams Applyonline - Application Form Builder AND Manager10/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline plugin <= 2.5 versions.
ModificadaAlta (8.8)2.0%—Microsoft Teams8/8/202310/8/2026
Microsoft Teams Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.2%—Microsoft Teams8/8/202310/8/2026
Microsoft Teams Remote Code Execution Vulnerability
ModificadaMedia (6.5)1.5%—Microsoft Teams11/7/202317/6/2026
Microsoft Teams Information Disclosure Vulnerability
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
Orbitaley — Vulnerabilidades