Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.5)0.66%—Tobit Laboratories AG Teamdavid WebboxAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the server, resulting in a denial of service.…
AplazadaAlta (8.9)0.41%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the provided path actually refers to an…
AplazadaAlta (8.5)0.52%—Tobit Laboratories AG Teamdavid WebboxAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-controlled content. This is possible because user input is written directly to files without proper validation or…
AplazadaMedia (6.3)0.49%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB…
AplazadaMedia (6.3)0.49%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB…
AplazadaMedia (6.3)0.49%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to…
AplazadaAlta (7.7)0.57%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This…
AplazadaCrítica (9.2)0.56%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including…
AplazadaAlta (8.5)0.45%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary…
AplazadaMedia (6.9)0.57%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error information or internal application details, potentially aiding in further attacks. This issue affects TeamDavid before Rollout 528. Starting…
AplazadaAlta (8.4)0.40%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place…
AplazadaMedia (5.3)0.45%—Tobit Laboratories AG Teamdavid WebboxAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link,…
AplazadaMedia (5.3)0.46%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as “%2e” (representing a dot), an attacker can manipulate the portion of the URL following the top-level domain…
AplazadaAlta (8.4)0.40%—Tobit Laboratories AG TeamdavidAI7/8/20267/9/2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid before Rollout 528. Starting with…
AnalizadaCrítica (10)0.80%—Microsoft Teams7/8/202611/8/2026
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.50%—Microsoft Teams7/8/20267/8/2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.6)0.69%—Microsoft Teams7/8/20267/8/2026
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (5.5)0.41%—Shandong Hoteam PDM Product Data Management SystemAI5/8/202612/8/2026
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is…
AplazadaAlta (8)0.40%—Teamviewer Full ClientAITeamviewer HostAI29/7/202630/7/2026
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitJetbrains Teamcity27/7/20266/8/2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
En análisisCrítica (9.1)0.66%—Jetbrains TeamcityAI23/7/202624/7/2026
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
AnalizadaCrítica (10)0.66%—Jetbrains Teamcity23/7/202611/8/2026
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
AplazadaAlta (8.9)0.91%—Frangoteam FuxaAI21/7/202623/7/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against the stored script's permission by ID, but when `test: true` is set in…
AplazadaAlta (7.7)0.57%—Frangoteam FuxaAI21/7/202623/7/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.
AplazadaAlta (8.9)0.84%—Frangoteam FuxaAI21/7/202623/7/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure…
Orbitaley — Vulnerabilidades