Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | |
| Analizada | Alta (7.4) | 0.54% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | |
| Modificada | Media (6.1) | 0.48% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | |
| Analizada | Media (6.5) | 0.43% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled | |
| Aplazada | Alta (7.1) | 0.39% | — | Photo Gallery Team Photo Gallery BY AYSAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Reflected XSS.This issue affects Photo Gallery by Ays: from n/a through 5.5.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | Teamviewer Remote ClientAI | 26/3/2024 | 17/6/2026 | Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink. | |
| Analizada | Alta (7.8) | 0.23% | — | Jetbrains Teamcity | 21/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | |
| Aplazada | Alta (7.1) | 0.33% | — | Ninjateam Database FOR Contact Form 7AI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam Database for Contact Form 7 allows Stored XSS.This issue affects Database for Contact Form 7: from n/a through 3.0.6. | |
| Analizada | Media (6.1) | 0.44% | — | Wpdarko Team Members | 18/3/2024 | 17/6/2026 | The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Media (4.3) | 0.20% | — | I13websolution Team Circle Image Slider With Lightbox | 13/3/2024 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_func() function. This makes it possible for unauthenticated attackers to edit… | |
| Analizada | Media (5) | 1.2% | — | Microsoft Teams | 12/3/2024 | 17/6/2026 | Microsoft Teams for Android Information Disclosure Vulnerability | |
| Analizada | Media (5.9) | 0.42% | — | Team-ever SEO | 8/3/2024 | 17/6/2026 | In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Media (5.4) | 0.37% | — | Ninjateam WP Chat APP | 7/3/2024 | 17/6/2026 | The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'buttonColor' and 'phoneNumber'. This makes it possible for… | |
| Analizada | Media (5.8) | 0.34% | — | Jetbrains Teamcity | 6/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | |
| Analizada | Media (4.3) | 0.53% | — | Jetbrains Teamcity | 6/3/2024 | 17/6/2026 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed | |
| Analizada | Alta (7.5) | 0.71% | — | Teamwire | 5/3/2024 | 17/6/2026 | An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function. | |
| Modificada | Crítica (9.6) | 0.87% | — | Teamwire | 5/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components. | |
| Modificada | Crítica (9.6) | 0.87% | — | Teamwire | 5/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. | |
| Analizada | Alta (7.3) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| Analizada | Alta (7.8) | 0.20% | — | Teamviewer Remote | 27/2/2024 | 17/6/2026 | Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account. | |
| Modificada | Media (5) | 0.97% | — | Microsoft Teams | 13/2/2024 | 10/8/2026 | Microsoft Teams for Android Information Disclosure Vulnerability | |
| Modificada | Media (4.8) | 0.34% | — | Ninjateam WP Chat APP | 12/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat App allows Stored XSS.This issue affects WP Chat App: from n/a through 3.4.4. | |
| Modificada | Media (6.5) | 0.46% | — | Badge.team Hacker Hotel Badge 2024 | 11/2/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on risc-v (billboard modules) allows Flooding.This issue affects Hacker Hotel Badge 2024: from 0.1.0 through 0.1.3. | |
| Modificada | Media (5.3) | 32% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives |