Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.58% | — | Digitalcorpora TcpflowDebian Linux | 29/1/2026 | 17/6/2026 | tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past `tim.bitmap[251]`. The… | |
| Analizada | Media (6.8) | 0.77% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected… | |
| Analizada | Media (6.5) | 0.66% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical… | |
| Analizada | Alta (7.5) | 0.37% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR… | |
| Analizada | Alta (8.1) | 0.21% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be… | |
| Analizada | Media (6.5) | 0.34% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted… | |
| Analizada | Media (6.5) | 0.16% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log… | |
| Analizada | Media (6.5) | 0.18% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content… | |
| Analizada | Media (6.5) | 0.13% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information. | |
| Analizada | Alta (7.1) | 0.23% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the… | |
| Analizada | Media (5.4) | 0.18% | — | Salsa.digital Mini Site | 28/1/2026 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2. | |
| Aplazada | Alta (8.9) | 0.61% | — | Westerndigital WD DiscoveryAI | 26/1/2026 | 17/6/2026 | DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path. | |
| Aplazada | Media (5.3) | 0.33% | — | Mwtemplates DeepdigitalAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in mwtemplates DeepDigital deepdigital allows Code Injection.This issue affects DeepDigital: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.8) | 0.43% | — | Digital Crime Report Management SystemAI | 21/1/2026 | 17/6/2026 | Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police,… | |
| Aplazada | Media (5.5) | 0.40% | — | Risesoft Y9 Digital-infrastructureAI | 17/1/2026 | 17/6/2026 | A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.1) | 0.18% | — | Chloedigital PrimerAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chloédigital PRIMER by chloédigital primer-by-chloedigital allows Reflected XSS.This issue affects PRIMER by chloédigital: from n/a through <= 1.0.25. | |
| Aplazada | Crítica (9.8) | 0.38% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 7/10/2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37. | |
| Aplazada | Alta (7.1) | 0.22% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25. | |
| Aplazada | Media (6.9) | 0.43% | — | Red-v Super Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication. | |
| Aplazada | Alta (8.7) | 0.37% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct… | |
| Aplazada | Media (5.1) | 0.17% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF… | |
| Aplazada | Alta (8.6) | 0.31% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP… | |
| Aplazada | Alta (8.5) | 0.26% | — | TDM Digital Signage PC PlayerAI | 6/1/2026 | 17/6/2026 | TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access. | |
| Aplazada | Alta (8.7) | 0.39% | — | Adtec Digital Signedje Digital Signage PlayerAI | 6/1/2026 | 17/6/2026 | Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product… | |
| Aplazada | Alta (8.6) | 0.31% | — | Qihang Media WEB Digital SignageAI | 6/1/2026 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication… |