Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
3692 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.25% | — | Gitea | 26/12/2025 | 17/6/2026 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. | |
| Analizada | Media (5.3) | 0.36% | — | Gitea | 26/12/2025 | 17/6/2026 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. | |
| Analizada | Media (5.3) | 0.28% | — | Gitea | 26/12/2025 | 17/6/2026 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. | |
| Analizada | Media (5.3) | 0.36% | — | Gitea | 26/12/2025 | 17/6/2026 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order. | |
| Analizada | Media (5.4) | 0.25% | — | Gitea | 26/12/2025 | 17/6/2026 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. | |
| Analizada | Media (5.3) | 0.26% | — | Gitea | 26/12/2025 | 17/6/2026 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. | |
| Analizada | Media (5.3) | 0.27% | — | Gitea | 26/12/2025 | 17/6/2026 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. | |
| Analizada | Media (5.3) | 0.33% | — | Gitea | 26/12/2025 | 17/6/2026 | Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API. | |
| Analizada | Media (5.3) | 0.38% | — | Gitea | 26/12/2025 | 17/6/2026 | Gitea before 1.25.2 mishandles authorization for deletion of releases. | |
| Aplazada | Alta (7.1) | 0.65% | — | Videoflow Digital Video Protection DVPAI | 24/12/2025 | 17/6/2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary system files through unvalidated 'ID' parameters. Attackers can exploit multiple Perl scripts like downloadsys.pl to read sensitive files by manipulating directory path… | |
| Aplazada | Alta (8.7) | 0.44% | — | Videoflow Digital Video Protection DVPAI | 24/12/2025 | 17/6/2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access. | |
| Modificada | Crítica (9.3) | 0.47% | — | Thedigitalcraft Atomcms | 22/12/2025 | 17/6/2026 | Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks. | |
| Aplazada | Crítica (9.1) | 0.69% | — | Redhat Openshift GitopsAIArgoproj ArgocdAI | 15/12/2025 | 7/10/2026 | A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run… | |
| Analizada | Media (6.1) | 0.27% | 💥 PoC | Digitaldruid Hoteldruid | 11/12/2025 | 17/6/2026 | HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. | |
| Analizada | Alta (8.6) | 0.39% | — | Github Enterprise Server | 11/12/2025 | 17/6/2026 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views,… | |
| Analizada | Media (6.7) | 0.17% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution,… | |
| Analizada | Media (6.7) | 0.18% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.83% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote… | |
| Analizada | Alta (7.2) | 1.1% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables… | |
| Analizada | Alta (7.2) | 1.2% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 1.2% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 1.2% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables… |