Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1221 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Mwtemplates DeepdigitalAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mwtemplates DeepDigital deepdigital allows Reflected XSS.This issue affects DeepDigital: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.4) | 0.14% | — | Digital Arts Finalcode ClientAI | 26/2/2026 | 17/6/2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privilege. | |
| Aplazada | Alta (8.5) | 0.11% | — | Digital Arts Finalcode ClientAI | 26/2/2026 | 17/6/2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Media (4.8) | 0.16% | — | Hcltech Digital Experience | 20/2/2026 | 17/6/2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit. | |
| Aplazada | Crítica (9.8) | 0.47% | 💥 PoC | Emit Informatics AND Communication Technologies Digita Efficiency Management SystemAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection. This issue affects DIGITA Efficiency Management System: through 03022026. NOTE: The… | |
| Analizada | Media (5.5) | 0.58% | — | Digitalcorpora TcpflowDebian Linux | 29/1/2026 | 17/6/2026 | tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past `tim.bitmap[251]`. The… | |
| Analizada | Media (6.8) | 0.77% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected… | |
| Analizada | Media (6.5) | 0.66% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical… | |
| Analizada | Alta (7.5) | 0.37% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR… | |
| Analizada | Alta (8.1) | 0.21% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be… | |
| Analizada | Media (6.5) | 0.34% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted… | |
| Analizada | Media (6.5) | 0.16% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log… | |
| Analizada | Media (6.5) | 0.18% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content… | |
| Analizada | Media (6.5) | 0.13% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information. | |
| Analizada | Alta (7.1) | 0.23% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the… | |
| Analizada | Media (5.4) | 0.18% | — | Salsa.digital Mini Site | 28/1/2026 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2. | |
| Aplazada | Alta (8.9) | 0.61% | — | Westerndigital WD DiscoveryAI | 26/1/2026 | 17/6/2026 | DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path. | |
| Aplazada | Media (5.3) | 0.33% | — | Mwtemplates DeepdigitalAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in mwtemplates DeepDigital deepdigital allows Code Injection.This issue affects DeepDigital: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.8) | 0.43% | — | Digital Crime Report Management SystemAI | 21/1/2026 | 17/6/2026 | Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police,… | |
| Aplazada | Media (5.5) | 0.40% | — | Risesoft Y9 Digital-infrastructureAI | 17/1/2026 | 17/6/2026 | A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.1) | 0.18% | — | Chloedigital PrimerAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chloédigital PRIMER by chloédigital primer-by-chloedigital allows Reflected XSS.This issue affects PRIMER by chloédigital: from n/a through <= 1.0.25. | |
| Aplazada | Crítica (9.8) | 0.38% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 7/10/2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37. | |
| Aplazada | Alta (7.1) | 0.22% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25. | |
| Aplazada | Media (6.9) | 0.43% | — | Red-v Super Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication. | |
| Aplazada | Alta (8.7) | 0.37% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct… |