Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.15% | — | M2team Nanazip | 12/5/2026 | 17/6/2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function… | |
| Analizada | Media (5.5) | 0.55% | — | Microsoft Teams | 12/5/2026 | 17/6/2026 | Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Alta (8.7) | 0.39% | — | Siemens Teamcenter | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contains hardcoded key which is used… | |
| Analizada | Alta (8.5) | 0.28% | — | Siemens Teamcenter | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter… | |
| Analizada | Alta (7.5) | 0.34% | — | Jetbrains Teamcity | 11/5/2026 | 17/6/2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | |
| Analizada | Media (6.5) | 0.86% | — | Microsoft Teams | 7/5/2026 | 17/6/2026 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | |
| Aplazada | Alta (7.6) | 0.23% | — | Wpmart Team MemberAI | 7/5/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. This issue affects Team Member: from n/a through 8.5. | |
| Aplazada | Media (6.9) | 0.41% | — | Shandong Hoteam Software PDM Product Data Management SystemAI | 4/5/2026 | 17/6/2026 | A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely.… | |
| Analizada | Alta (8.7) | 0.66% | — | Teamt5 Threatsonar Anti-ransomware | 20/4/2026 | 17/6/2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges. | |
| Analizada | Alta (7.2) | 0.64% | — | Teamt5 Threatsonar Anti-ransomware | 20/4/2026 | 17/6/2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system. | |
| Analizada | Media (5.3) | 0.28% | — | Wimi-teamwork | 8/4/2026 | 24/7/2026 | Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other users' private or… | |
| Aplazada | Media (5.3) | 0.29% | — | Mulika Team Mipl WC Multisite SyncAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Mulika Team MIPL WC Multisite Sync mipl-wc-multisite-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MIPL WC Multisite Sync: from n/a through <= 1.4.4. | |
| Aplazada | Media (4.3) | 0.23% | — | Magepeopleteam Wptravelly Tour-booking-managerAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7. | |
| Aplazada | Media (5.5) | 0.47% | — | Shandong Hoteam Inforcenter PLMAI | 1/4/2026 | 17/6/2026 | A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available… | |
| Analizada | Crítica (9.3) | 0.23% | — | Teampass | 31/3/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicious JavaScript… | |
| Analizada | Crítica (9.3) | 0.27% | — | Teampass | 31/3/2026 | 17/6/2026 | Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in… | |
| Aplazada | Media (5.4) | 0.23% | — | WP Folio Team PpwpAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPWP: from n/a through <= 1.9.15. | |
| Aplazada | Alta (8.2) | 0.38% | — | Devteam Products-rearrange-woocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Devteam Product Rearrange FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.8) | 0.55% | — | Aa-team WzoneAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31. | |
| Aplazada | Alta (8.5) | 0.36% | — | Aa-team WzoneAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This issue affects WZone: from n/a through <= 14.0.31. | |
| Aplazada | Alta (7.1) | 0.18% | — | Magepeopleteam WpeventlyAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through <= 5.1.4. | |
| Aplazada | Alta (7.5) | 0.28% | — | Radiustheme Tlp-teamAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11. | |
| Aplazada | Media (6.5) | 0.30% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0. | |
| Aplazada | Alta (8.6) | 0.50% | — | Teamjcd JoycondroidAI | 24/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app/src/main/java/com/rdapps/gamepad/util modules). This vulnerability is associated with program files UnzipUtil.Java. This issue affects JoyConDroid: through 1.0.93. |