Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | Teampass | 10/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (4.6) | 0.52% | — | Teampass | 10/6/2023 | 17/6/2026 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Team Circle Image Slider With Lightbox | 9/6/2023 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Alta (7.8) | 0.26% | — | Siemens Jt2goSiemens Teamcenter Visualization | 7/6/2023 | 17/6/2026 | Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process. | |
| Modificada | Crítica (9.8) | 1.7% | — | Ninjateam Gpdr Ccpa Compliance Support | 7/6/2023 | 17/6/2026 | The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object. | |
| Modificada | Media (6.5) | 0.38% | — | Teampass | 4/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Crítica (9) | 0.91% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.1) | 0.84% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.7) | 0.74% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (5.4) | 1.0% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible | |
| Modificada | Media (6.5) | 0.40% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | |
| Modificada | Alta (7.5) | 0.52% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks | |
| Modificada | Media (6.1) | 1.0% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible | |
| Modificada | Media (5.4) | 61% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible | |
| Modificada | Media (4.8) | 0.35% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible | |
| Modificada | Media (5.3) | 1.3% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | |
| Modificada | Media (6.1) | 1.0% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible | |
| Modificada | Media (5.4) | 1.0% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible | |
| Modificada | Media (5.4) | 61% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible | |
| Modificada | Media (4.3) | 0.35% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API | |
| Modificada | Crítica (9.8) | 0.59% | — | Jetbrains Teamcity | 31/5/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | |
| Modificada | Media (5.4) | 0.68% | 💥 PoC | Teampass | 31/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.8) | 1.6% | 💥 PoC | Teampass | 24/5/2023 | 17/6/2026 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (5.4) | 0.37% | — | Wpmart Team Member - Team With Slider | 9/5/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Sk. Abul Hasan Team Member – Team with Slider plugin <= 4.4 versions. | |
| Modificada | Media (5.4) | 0.61% | 💥 PoC | Teampass | 9/5/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7. |