Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible | |
| Analizada | Media (6.1) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible | |
| Analizada | Media (5.4) | 0.26% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible | |
| Analizada | Media (6.1) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible | |
| Analizada | Media (6.1) | 0.28% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations | |
| Analizada | Alta (8.1) | 0.28% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent | |
| Analizada | Media (6.5) | 0.33% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible | |
| Analizada | Media (6.5) | 0.50% | — | Jetbrains Teamcity | 29/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible | |
| Aplazada | Media (6.4) | 0.11% | — | Teamviewer ClientAI | 28/5/2024 | 17/6/2026 | Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading. | |
| Aplazada | Alta (8.8) | 0.51% | — | Aa-team WzoneAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10. | |
| Aplazada | Media (5.3) | 0.49% | — | Stefano Lissa AND THE Newsletter Team NewsletterAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0. | |
| Analizada | Media (6.1) | 0.27% | — | Jetbrains Teamcity | 16/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible | |
| Analizada | Media (5.5) | 0.27% | — | Jetbrains Teamcity | 16/5/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token | |
| Analizada | Media (6.1) | 0.29% | — | Jetbrains Teamcity | 16/5/2024 | 17/6/2026 | In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible | |
| Analizada | Alta (7.8) | 0.24% | — | Siemens Jt2goSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), Teamcenter Visualization V14.3 (All versions < V14.3.0.7), Teamcenter Visualization V2312 (All versions < V2312.0001). The… | |
| Analizada | Alta (7.8) | 0.24% | — | Siemens Jt2goSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), Teamcenter Visualization V14.3 (All versions < V14.3.0.7), Teamcenter Visualization V2312 (All versions < V2312.0001). The… | |
| Analizada | Media (4.8) | 0.24% | — | Siemens Jt2goSiemens ParasolidSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain a null pointer dereference… | |
| Analizada | Alta (7.3) | 0.26% | — | Siemens Jt2goSiemens ParasolidSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain an out of bounds read past the… | |
| Analizada | Alta (7.3) | 0.28% | — | Siemens Jt2goSiemens ParasolidSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain an out of bounds read past the… | |
| Modificada | Alta (7.5) | 0.57% | — | Ninjateam Filebird | 14/5/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3. | |
| Aplazada | Alta (7.1) | 0.18% | — | Popup BOX Team Popup BOXAI | 6/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a through 4.1.2. |