Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (2.3)0.26%—Openclaw MS TeamsAI17/7/202617/7/2026
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.
AplazadaAlta (8.5)0.16%—Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+614/7/20265/10/2026
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter…
AplazadaMedia (5.3)0.29%—Magepeopleteam CAR Rental ManagerAI13/7/202613/7/2026
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.
AplazadaAlta (7.1)0.25%—Acymailing Newsletter Team Acymailing Smtp NewsletterAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
AplazadaMedia (6.5)0.33%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.
AplazadaBaja (2.4)0.16%—M2team NanazipAI10/7/202610/7/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-house IInArchive handlers in NanaZip.Codecs unconditionally dereference the caller-supplied Indices array inside Extract when the archive engine signals extract everything by passing Indices as NULL and…
AplazadaBaja (2.4)0.16%—M2team NanazipAI10/7/202614/7/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in…
AplazadaBaja (2.4)0.16%💥 PoCM2team NanazipAI10/7/202610/7/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize fragment size, allowing attacker-controlled…
AplazadaBaja (2.4)0.42%💥 ExploitM2team NanazipAI10/7/202613/7/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign and is not validated against the real…
AnalizadaAlta (8.1)0.35%—Jetbrains Teamcity10/7/202614/7/2026
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
AnalizadaMedia (6.1)0.34%—Jetbrains Teamcity10/7/202613/7/2026
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
AnalizadaMedia (5.4)0.32%—Jetbrains Teamcity10/7/202610/7/2026
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
AnalizadaAlta (8.8)0.49%—Jetbrains Teamcity10/7/202614/7/2026
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
AplazadaAlta (8.7)0.61%—Frangoteam FuxaAI30/6/20261/7/2026
FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticated requests to access protected endpoints by prefixing paths with…
AplazadaMedia (4.4)0.34%—Team Members Multi Language Supported Team PluginAI30/6/202630/6/2026
The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaCrítica (9.6)0.50%—Ninjateam FastdupAI15/6/202617/6/2026
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
AplazadaMedia (5.4)0.31%—7-zipAIM2team NanazipAI12/6/202617/6/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). A 32-bit unsigned integer overflow in the bounds…
AplazadaMedia (4.3)0.32%—7-zipAIM2team NanazipAI12/6/202617/6/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the LVM2 physical-volume metadata parser in NanaZip (via the upstream 7-Zip LvmHandler). The vulnerability is triggered when opening a crafted LVM disk…
AplazadaMedia (5.4)0.29%—7-zipAIM2team NanazipAI12/6/202617/6/2026
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). An unsigned integer underflow in a bounds check…
AnalizadaAlta (8.1)1.2%—Microsoft Teams9/6/202623/7/2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
ModificadaMedia (6.5)0.31%—Team Net\4/6/202622/7/2026
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
AplazadaAlta (7)0.66%—NanobotAIMicrosoft TeamsAIMicrosoft BOT FrameworkAI1/6/202622/7/2026
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation…
Pendiente de análisisCrítica (9.8)0.81%—Catia Magic Collaboration StudioAI3DS Teamwork CloudAI1/6/202622/7/2026
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.
AnalizadaMedia (4.8)0.29%—Jetbrains Teamcity29/5/202622/7/2026
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
AnalizadaMedia (6.1)0.23%—Jetbrains Teamcity29/5/202622/7/2026
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Orbitaley — Vulnerabilidades