Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.15%—M2team Nanazip12/5/202617/6/2026
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function…
AnalizadaMedia (5.5)0.55%—Microsoft Teams12/5/202617/6/2026
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
AnalizadaAlta (8.7)0.39%—Siemens Teamcenter12/5/202617/6/2026
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contains hardcoded key which is used…
AnalizadaAlta (8.5)0.28%—Siemens Teamcenter12/5/202617/6/2026
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter…
AnalizadaAlta (7.5)0.34%—Jetbrains Teamcity11/5/202617/6/2026
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
AnalizadaMedia (6.5)0.86%—Microsoft Teams7/5/202617/6/2026
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
AplazadaAlta (7.6)0.23%—Wpmart Team MemberAI7/5/20267/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. This issue affects Team Member: from n/a through 8.5.
AplazadaMedia (6.9)0.41%—Shandong Hoteam Software PDM Product Data Management SystemAI4/5/202617/6/2026
A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely.…
AnalizadaAlta (8.7)0.66%—Teamt5 Threatsonar Anti-ransomware20/4/202617/6/2026
ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges.
AnalizadaAlta (7.2)0.64%—Teamt5 Threatsonar Anti-ransomware20/4/202617/6/2026
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
AnalizadaMedia (5.3)0.28%—Wimi-teamwork8/4/202624/7/2026
Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other users' private or…
AplazadaMedia (5.3)0.29%—Mulika Team Mipl WC Multisite SyncAI8/4/202624/7/2026
Missing Authorization vulnerability in Mulika Team MIPL WC Multisite Sync mipl-wc-multisite-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MIPL WC Multisite Sync: from n/a through <= 1.4.4.
AplazadaMedia (4.3)0.23%—Magepeopleteam Wptravelly Tour-booking-managerAI8/4/202620/7/2026
Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7.
AplazadaMedia (5.5)0.47%—Shandong Hoteam Inforcenter PLMAI1/4/202617/6/2026
A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available…
AnalizadaCrítica (9.3)0.23%—Teampass31/3/202617/6/2026
Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicious JavaScript…
AnalizadaCrítica (9.3)0.27%—Teampass31/3/202617/6/2026
Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in…
AplazadaMedia (5.4)0.23%—WP Folio Team PpwpAI25/3/202617/6/2026
Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPWP: from n/a through <= 1.9.15.
AplazadaAlta (8.2)0.38%—Devteam Products-rearrange-woocommerceAI25/3/202617/6/2026
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2.
AplazadaCrítica (9.3)0.40%—Devteam Product Rearrange FOR WoocommerceAI25/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2.
AplazadaAlta (8.8)0.55%—Aa-team WzoneAI25/3/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31.
AplazadaAlta (8.5)0.36%—Aa-team WzoneAI25/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This issue affects WZone: from n/a through <= 14.0.31.
AplazadaAlta (7.1)0.18%—Magepeopleteam WpeventlyAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through <= 5.1.4.
AplazadaAlta (7.5)0.28%—Radiustheme Tlp-teamAI25/3/202617/6/2026
Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11.
AplazadaMedia (6.5)0.30%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI25/3/202617/6/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0.
AplazadaAlta (8.6)0.50%—Teamjcd JoycondroidAI24/3/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app/src/main/java/com/rdapps/gamepad/util modules). This vulnerability is associated with program files UnzipUtil.Java‎. This issue affects JoyConDroid: through 1.0.93.
Orbitaley — Vulnerabilidades