Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.31%—Pickplugins Team Showcase18/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a through <= 1.22.25.
AnalizadaMedia (4.8)0.36%—Ninjateam Header Footer Custom Code13/9/202417/6/2026
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (4.8)0.34%—Ninjateam Header Footer Custom Code13/9/202417/6/2026
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (5.3)0.49%—Project Team Tmall Demo8/9/202417/6/2026
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (4.3)0.42%—Teamviewer MeetingTeamviewer28/8/202417/6/2026
Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting.
AplazadaMedia (6.5)0.26%—Pickplugins Team ShowcaseAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23.
AnalizadaMedia (5.4)0.27%—Jetbrains Teamcity16/8/202417/6/2026
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
AnalizadaMedia (6.1)0.33%—Jetbrains Teamcity16/8/202417/6/2026
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
AnalizadaMedia (5.4)0.24%—Jetbrains Teamcity16/8/202417/6/2026
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
AnalizadaMedia (5.4)0.31%—Jetbrains Teamcity16/8/202417/6/2026
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
AnalizadaMedia (6.5)16%—Microsoft Teams13/8/202417/6/2026
Microsoft Teams for iOS Spoofing Vulnerability
AnalizadaAlta (7.2)1.8%⚠ Explotación activaTeamt5 Threatsonar Anti-ransomware12/8/202417/6/2026
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
AnalizadaCrítica (9)0.79%—Vrcx-team Vrcx8/8/202417/6/2026
VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be combined to result in remote command execution. These vulnerabilities are patched in VRCX 2023.12.24. In addition to the patch, VRCX…
AnalizadaAlta (7.8)0.15%—Jetbrains Teamcity6/8/202417/6/2026
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
AnalizadaAlta (8.8)0.62%—Ninjateam Filester3/8/202417/6/2026
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted…
ModificadaAlta (7.5)0.33%—Jetbrains Teamcity22/7/202417/6/2026
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
ModificadaMedia (6.5)0.28%—Jetbrains Teamcity22/7/202417/6/2026
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
ModificadaCrítica (9.8)0.40%—Jetbrains Teamcity22/7/202417/6/2026
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
ModificadaMedia (4.8)0.30%—Jetbrains Teamcity22/7/202417/6/2026
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
ModificadaMedia (5.4)0.27%—Jetbrains Teamcity22/7/202417/6/2026
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
ModificadaMedia (6.5)0.30%—Jetbrains Teamcity22/7/202417/6/2026
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
ModificadaMedia (5.4)0.26%—Sinatrateam Sinatra22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3.
AplazadaMedia (6.5)0.29%—Gutenberg Team GutenbergAI21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutenberg Team Gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through 18.6.0.
AplazadaMedia (6.5)0.34%—Wpdarko Team MembersAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3.
AnalizadaMedia (6.5)0.42%—Cisco Webex Teams17/7/202417/6/2026
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a…