Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | |
| Analizada | Media (4.3) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | |
| Analizada | Media (4.3) | 0.92% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | |
| Analizada | Media (6.5) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | |
| Analizada | Media (6.1) | 0.30% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | |
| Analizada | Alta (7.6) | 0.31% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | |
| Analizada | Alta (8.8) | 0.60% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | |
| Analizada | Alta (7.5) | 0.39% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | |
| Analizada | Alta (8.2) | 0.35% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | |
| Aplazada | Media (6.9) | 0.64% | — | Teamspeak 3 ServerAI | 27/5/2026 | 17/6/2026 | A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the component clientek Handshake Handler. Performing a manipulation of the argument proof results in reachable assertion. Remote exploitation of the attack is possible. Upgrading to version 3.13.8 is capable… | |
| Aplazada | Media (6.9) | 0.69% | — | Teamspeak 3 ServerAI | 27/5/2026 | 17/6/2026 | A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such manipulation leads to heap-based buffer overflow. The attack may be launched remotely. Upgrading to version 3.13.8 is able to resolve this issue. It is suggested… | |
| Aplazada | Media (5.3) | 0.41% | 💥 PoC | Teamspeak 3 ServerAI | 27/5/2026 | 17/6/2026 | A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation causes use after free. The attack may be initiated remotely. Upgrading to version 3.13.8 is able to mitigate this issue. The affected… | |
| Aplazada | Crítica (9.8) | 0.53% | 💥 PoC | Saleswonder Team Webinar IgnitionAI | 27/5/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Saleswonder Team Webinar IgnitionAI | 27/5/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253. | |
| Aplazada | Media (6.4) | 0.26% | — | Team Master Modern Wordpress Team Showcase Team MasterAI | 27/5/2026 | 17/6/2026 | The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.25% | — | Aa-team Woocommerce Envato AffiliatesAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Pickplugins Team ShowcaseAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Teamviewer DEX PlatformAI | 22/5/2026 | 23/7/2026 | A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles.… | |
| Pendiente de análisis | Media (6.3) | 0.34% | — | Teamviewer DEX Platform On-premisesAI | 13/5/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution… | |
| Analizada | Alta (7.1) | 0.26% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS filesystem image. The attacker controls the byte offset of the write within a… | |
| Analizada | Alta (7.1) | 0.16% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted ZealFS v1 filesystem image. An attacker-controlled BitmapSize field in the file header drives an… | |
| Analizada | Media (5.5) | 0.15% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPaths recurses into subdirectories without any depth limit or visited-inode tracking. A crafted UFS image with a deep… | |
| Analizada | Media (5.5) | 0.15% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method reads BlockCount directly from the attacker-controlled superblock without any validation against the actual file size or… | |
| Analizada | Media (5.5) | 0.15% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the superblock field fs_ipg (inodes per cylinder group) is set to zero. The parser… | |
| Analizada | Media (5.5) | 0.15% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the root inode (inode 2) is set to IFLNK (symlink) instead of IFDIR (directory). The… |