Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.31% | — | Pickplugins Team Showcase | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a through <= 1.22.25. | |
| Analizada | Media (4.8) | 0.36% | — | Ninjateam Header Footer Custom Code | 13/9/2024 | 17/6/2026 | The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (4.8) | 0.34% | — | Ninjateam Header Footer Custom Code | 13/9/2024 | 17/6/2026 | The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (5.3) | 0.49% | — | Project Team Tmall Demo | 8/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (4.3) | 0.42% | — | Teamviewer MeetingTeamviewer | 28/8/2024 | 17/6/2026 | Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting. | |
| Aplazada | Media (6.5) | 0.26% | — | Pickplugins Team ShowcaseAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23. | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin | |
| Analizada | Media (6.1) | 0.33% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page | |
| Analizada | Media (5.4) | 0.24% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin | |
| Analizada | Media (5.4) | 0.31% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page | |
| Analizada | Media (6.5) | 16% | — | Microsoft Teams | 13/8/2024 | 17/6/2026 | Microsoft Teams for iOS Spoofing Vulnerability | |
| Analizada | Alta (7.2) | 1.8% | ⚠ Explotación activa | Teamt5 Threatsonar Anti-ransomware | 12/8/2024 | 17/6/2026 | ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server. | |
| Analizada | Crítica (9) | 0.79% | — | Vrcx-team Vrcx | 8/8/2024 | 17/6/2026 | VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be combined to result in remote command execution. These vulnerabilities are patched in VRCX 2023.12.24. In addition to the patch, VRCX… | |
| Analizada | Alta (7.8) | 0.15% | — | Jetbrains Teamcity | 6/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | |
| Analizada | Alta (8.8) | 0.62% | — | Ninjateam Filester | 3/8/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted… | |
| Modificada | Alta (7.5) | 0.33% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | |
| Modificada | Media (6.5) | 0.28% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time | |
| Modificada | Crítica (9.8) | 0.40% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | |
| Modificada | Media (4.8) | 0.30% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | |
| Modificada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab | |
| Modificada | Media (6.5) | 0.30% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases | |
| Modificada | Media (5.4) | 0.26% | — | Sinatrateam Sinatra | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3. | |
| Aplazada | Media (6.5) | 0.29% | — | Gutenberg Team GutenbergAI | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutenberg Team Gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through 18.6.0. | |
| Aplazada | Media (6.5) | 0.34% | — | Wpdarko Team MembersAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3. | |
| Analizada | Media (6.5) | 0.42% | — | Cisco Webex Teams | 17/7/2024 | 17/6/2026 | A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a… |