Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

235 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.68%💥 PoCTeampass31/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaAlta (8.8)1.6%💥 PoCTeampass24/5/202317/6/2026
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaMedia (5.4)0.46%—Activecampaign15/5/202317/6/2026
The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.61%💥 PoCTeampass9/5/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
ModificadaMedia (5.4)0.61%💥 PoCTeampass5/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
ModificadaCrítica (9.1)1.5%—Apache Streampark1/5/202317/6/2026
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to…
ModificadaCrítica (9.8)1.3%—Apache Streampark1/5/202317/6/2026
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
ModificadaMedia (5.4)1.1%—Apache Streampark1/5/202317/6/2026
Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements through techniques similar to…
ModificadaAlta (7.5)1.5%—Powerampapp Poweramp14/4/202317/6/2026
An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library
ModificadaMedia (5.4)0.36%—Teampass13/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.
ModificadaCrítica (9.8)1.5%—Powerampapp Poweramp11/4/202317/6/2026
An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.
ModificadaAlta (7.5)8.4%💥 ExploitTeampass21/3/202317/6/2026
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
ModificadaMedia (5.4)0.52%—Teampass17/3/202317/6/2026
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
ModificadaMedia (5.4)0.44%—Campaign URL Builder Project Campaign URL Builder13/3/202317/6/2026
The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.1)0.82%—Teampass27/2/202317/6/2026
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
ModificadaAlta (8.8)0.75%—Ampache10/2/202317/6/2026
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
ModificadaMedia (6.1)0.64%—Ampache1/2/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
ModificadaMedia (4.3)0.48%—Activecampaign FOR Woocommerce9/1/202317/6/2026
The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.
ModificadaAlta (8.8)0.78%—Ampache23/12/202217/6/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
ModificadaMedia (6.5)1.4%—Adobe Campaign16/12/20226/8/2026
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation…
ModificadaMedia (6.1)1.1%—Teampass28/3/202217/6/2026
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.
ModificadaAlta (7.5)0.79%—Teampasswordmanager Team Password Manager19/11/202117/6/2026
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
ModificadaAlta (8.8)0.43%—Teampasswordmanager Team Password Manager19/11/202117/6/2026
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
ModificadaAlta (7.5)3.7%—Adobe Campaign17/11/202117/6/2026
Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.
ModificadaMedia (5.4)0.84%💥 PoCAmpache22/6/202117/6/2026
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been…
Orbitaley — Vulnerabilidades