Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.41% | — | Ultravnc ViewerAI | 5/2/2026 | 17/6/2026 | UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash. | |
| Aplazada | Alta (8.4) | 0.53% | — | Microdicom Dicom ViewerAI | 5/2/2026 | 17/6/2026 | Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by overwriting SEH and triggering remote code… | |
| Aplazada | Alta (7.2) | 0.32% | — | Teamviewer FullAITeamviewer HostAI | 5/2/2026 | 17/6/2026 | Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an authenticated user to bypass additional access controls with “Allow after confirmation” configuration in a remote session. An exploit could result in unauthorized access prior to local confirmation.… | |
| Aplazada | Alta (7.2) | 0.33% | — | ALL IN ONE Image Viewer BlockAI | 5/2/2026 | 17/6/2026 | The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Ninguna (0) | 0.32% | — | Wikimedia MultimediaviewerAI | 2/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Pexlechris Library ViewerAI | 2/2/2026 | 17/6/2026 | The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (8.4) | 0.46% | — | Gnome Fonts ViewerAI | 29/1/2026 | 17/6/2026 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to exhaust memory through repeated malloc() calls and potentially crash the… | |
| Analizada | Media (6.8) | 0.77% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected… | |
| Analizada | Media (6.5) | 0.66% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical… | |
| Analizada | Alta (7.5) | 0.37% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR… | |
| Analizada | Alta (8.1) | 0.21% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be… | |
| Analizada | Media (6.5) | 0.34% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted… | |
| Analizada | Media (6.5) | 0.16% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log… | |
| Analizada | Media (6.5) | 0.18% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content… | |
| Analizada | Media (6.5) | 0.13% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information. | |
| Analizada | Alta (7.1) | 0.23% | — | Teamviewer Digital Employee Experience | 29/1/2026 | 17/6/2026 | Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the… | |
| Aplazada | Media (4.3) | 0.26% | — | Topdevs Smart Product ViewerAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in topdevs Smart Product Viewer smart-product-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Product Viewer: from n/a through <= 1.5.4. | |
| Aplazada | Media (4.9) | 0.22% | — | Marcomilesi Anac XML ViewerAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Request Forgery.This issue affects ANAC XML Viewer: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.1) | 0.43% | — | Novarad Novapacs Diagnostics ViewerAI | 24/12/2025 | 17/6/2026 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Aplazada | Alta (8.8) | 0.50% | — | Wp3d Model Import ViewerAI | 13/12/2025 | 30/9/2026 | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary… | |
| Analizada | Media (6.7) | 0.17% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution,… | |
| Analizada | Media (6.7) | 0.18% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… |