Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Jetbrains Teamcity28/3/202417/6/2026
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
AnalizadaAlta (7.4)0.54%—Jetbrains Teamcity28/3/202417/6/2026
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
ModificadaMedia (6.1)0.48%—Jetbrains Teamcity28/3/202417/6/2026
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
AnalizadaMedia (6.5)0.43%—Jetbrains Teamcity28/3/202417/6/2026
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
AplazadaAlta (7.1)0.39%—Photo Gallery Team Photo Gallery BY AYSAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Reflected XSS.This issue affects Photo Gallery by Ays: from n/a through 5.5.2.
AplazadaAlta (7.1)0.21%—Teamviewer Remote ClientAI26/3/202417/6/2026
Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink.
AnalizadaAlta (7.8)0.23%—Jetbrains Teamcity21/3/202417/6/2026
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
AplazadaAlta (7.1)0.33%—Ninjateam Database FOR Contact Form 7AI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam Database for Contact Form 7 allows Stored XSS.This issue affects Database for Contact Form 7: from n/a through 3.0.6.
AnalizadaMedia (6.1)0.44%—Wpdarko Team Members18/3/202417/6/2026
The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.
AnalizadaMedia (4.3)0.20%—I13websolution Team Circle Image Slider With Lightbox13/3/202417/6/2026
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_func() function. This makes it possible for unauthenticated attackers to edit…
AnalizadaMedia (5)1.2%—Microsoft Teams12/3/202417/6/2026
Microsoft Teams for Android Information Disclosure Vulnerability
AnalizadaMedia (5.9)0.42%—Team-ever SEO8/3/202417/6/2026
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.
ModificadaMedia (5.4)0.37%—Ninjateam WP Chat APP7/3/202417/6/2026
The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'buttonColor' and 'phoneNumber'. This makes it possible for…
AnalizadaMedia (5.8)0.34%—Jetbrains Teamcity6/3/202417/6/2026
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
AnalizadaMedia (4.3)0.53%—Jetbrains Teamcity6/3/202417/6/2026
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
AnalizadaAlta (7.5)0.71%—Teamwire5/3/202417/6/2026
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.
ModificadaCrítica (9.6)0.87%—Teamwire5/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.
ModificadaCrítica (9.6)0.87%—Teamwire5/3/202417/6/2026
Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.
AnalizadaAlta (7.3)100%⚠ Explotación activa💥 ExploitJetbrains Teamcity4/3/202417/6/2026
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitJetbrains Teamcity4/3/202417/6/2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
AnalizadaAlta (7.8)0.20%—Teamviewer Remote27/2/202417/6/2026
Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account.
ModificadaMedia (5)0.97%—Microsoft Teams13/2/202410/8/2026
Microsoft Teams for Android Information Disclosure Vulnerability
ModificadaMedia (4.8)0.34%—Ninjateam WP Chat APP12/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat App allows Stored XSS.This issue affects WP Chat App: from n/a through 3.4.4.
ModificadaMedia (6.5)0.46%—Badge.team Hacker Hotel Badge 202411/2/202417/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on risc-v (billboard modules) allows Flooding.This issue affects Hacker Hotel Badge 2024: from 0.1.0 through 0.1.3.
ModificadaMedia (5.3)32%—Jetbrains Teamcity6/2/202417/6/2026
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
Orbitaley — Vulnerabilidades