Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.38% | — | Cisco Webex MeetingsCisco Webex Teams | 26/11/2019 | 17/6/2026 | A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due… | |
| Modificada | Media (6.5) | 1.0% | — | Weaver Eteams OA | 9/9/2019 | 17/6/2026 | An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/. | |
| Modificada | Alta (8.8) | 4.3% | — | Cisco Webex Teams | 5/9/2019 | 17/6/2026 | A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging features used by the application on Windows operating systems. An attacker could… | |
| Modificada | Alta (7.5) | 1.7% | — | Teamspeak | 29/8/2019 | 17/6/2026 | The TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte sequence, aka Unicode characters U+2068 (FIRST STRONG ISOLATE) and U+2067 (RIGHT-TO-LEFT ISOLATE). | |
| Modificada | Alta (8.8) | 3.9% | — | Teamspeak | 19/4/2019 | 17/6/2026 | TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework. | |
| Modificada | Alta (7.8) | 4.6% | — | Microsoft Teams | 12/3/2019 | 17/6/2026 | Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.3) | 1.6% | — | Cisco Webex Teams | 25/2/2019 | 17/6/2026 | A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, remote attacker to upload arbitrary files within the scope of the iOS application. The vulnerability is due to improper input validation in the client application. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.8) | 47% | — | Cisco Webex Teams | 23/1/2019 | 17/6/2026 | A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating systems. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.7) | 1.3% | — | Cisco Webex Teams | 5/10/2018 | 17/6/2026 | A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for associations between user accounts and… | |
| Modificada | Alta (8.8) | 3.1% | — | Cisco Webex Teams | 18/7/2018 | 17/6/2026 | A vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's device, possibly with elevated privileges. The vulnerability occurs because Cisco Webex Teams does not properly sanitize input. An attacker could exploit the… | |
| Modificada | Media (6.5) | 11% | 💥 Exploit | Teamspeak3 | 8/1/2018 | 17/6/2026 | Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab with two \\ (backslash) characters, a digit, a \ (backslash) character,… | |
| Modificada | Media (6.5) | 11% | 💥 Exploit | Teamspeak3 | 8/1/2018 | 17/6/2026 | TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab containing [img]//http:// substrings. | |
| Modificada | Alta (7.5) | 1.4% | — | Teamspeak ServerTeamspeak Client | 6/7/2017 | 17/6/2026 | A potential Buffer Overflow Vulnerability (from a BB Code handling issue) has been identified in TeamSpeak Server version 3.0.13.6 (08/11/2016 09:48:33), it enables the users to Crash any WINDOWS Client that clicked into a Vulnerable Channel of a TeamSpeak Server. | |
| Modificada | Alta (7.5) | 2.5% | — | Teamspeak Client | 27/6/2017 | 17/6/2026 | TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode character followed by the ༿ Unicode character. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Teamst Testlink | 15/9/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator's email via an editUser action to… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomlamo COM Teams | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the Teams (com_teams) component 1_1028_100809_1711 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PlayerID parameter in a player save action to index.php. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Jikaka Teams Structure Module | 20/1/2011 | 16/6/2026 | SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the team_id parameter. | |
| Modificada | Media (6.9) | 0.38% | — | Teamspeak | 20/10/2010 | 16/6/2026 | The (1) teamspeak and (2) teamspeak-server scripts in TeamSpeak 2.0.32 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (4.3) | 0.85% | — | Robertotto Teamsite Hack Plugin | 9/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a modboard action, which is not properly handled in a forced SQL error message. NOTE: the provenance… | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Robertotto Teamsite Hack Plugin | 9/4/2010 | 16/6/2026 | SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action. | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Teamst Testlink | 10/12/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php. | |
| Modificada | Baja (3.5) | 3.3% | 💥 Exploit | Teamst Testlink | 10/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the req parameter to login.php, and allow remote authenticated users to inject arbitrary web script or HTML via (2) the key parameter to lib/general/staticPage.php, (3) the… | |
| Modificada | Media (4.3) | 1.0% | — | Teamst Testlink | 31/12/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) Testproject Names and (2) Testplan Names in planEdit.php, and possibly (3) Testcaseprefixes in projectview.tpl. | |
| Modificada | Alta (8.5) | 2.0% | — | Teamspeak WEB Server | 25/8/2007 | 16/6/2026 | The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3)… | |
| Modificada | Media (4.3) | 1.3% | — | Teamspeak WEB Server | 25/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html. |