Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.40%—Ixray-team Ixray-1.6-stcopAI24/3/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
AnalizadaMedia (4.3)0.18%—Mattermost MS Teams16/3/202617/6/2026
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
ModificadaAlta (7.1)0.54%—Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+616/3/202617/6/2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (5.3)0.26%—Radiustheme Tlp-teamAI13/3/202617/6/2026
Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13.
AplazadaAlta (7.5)0.51%—Magepeopleteam WpbookinglyAI13/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly service-booking-manager allows PHP Local File Inclusion.This issue affects WpBookingly: from n/a through <= 1.2.9.
AplazadaAlta (7.5)0.51%—Redqteam Turbo ManagerAIPHPAI13/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8.
AplazadaMedia (5.3)0.33%—Magepeopleteam WpeventlyAIMagepeopleteam Mage-eventpressAI13/3/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retrieve Embedded Sensitive Data.This issue affects WpEvently: from n/a through < 5.1.9.
AplazadaAlta (7.1)0.46%—2-plan TeamAI6/3/202617/6/2026
2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executable PHP files by sending multipart form data to managefile.php. Attackers can upload PHP files through the userfile1 parameter with action=upload, which are stored in the files directory and executed…
AnalizadaAlta (7.8)0.18%—Natroteam Natro Macro6/3/202617/6/2026
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code contained inside of a pattern or path file is executed by the macro. Since users commonly share path/pattern files, an attacker could share a file containing malicious code, which is then executed by the…
AnalizadaAlta (8)0.35%—Natroteam Natro Macro6/3/202617/6/2026
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-private channel gives access to any user with the permission to send message in said channel access to do anything on their computer. This includes keyboard and…
AplazadaAlta (8.1)0.52%—Ancorathemes FixteamAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes FixTeam fixteam allows PHP Local File Inclusion.This issue affects FixTeam: from n/a through <= 1.5.0.
AnalizadaMedia (5.1)0.16%—M2team Nanazip26/2/202617/6/2026
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory access during archive open/listing. The bug is reachable via normal…
AnalizadaMedia (5.1)0.14%—M2team Nanazip26/2/202617/6/2026
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer underflow in header-size calculation and trigger an unbounded memory…
AnalizadaMedia (5.1)0.16%—M2team Nanazip26/2/202617/6/2026
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulnerability in manifest parsing. A crafted bundle can provide a malformed `RelativePathLength` so the parser constructs a…
AnalizadaBaja (2.3)0.17%—Jetbrains Teamcity25/2/202617/6/2026
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
AnalizadaMedia (4.3)0.26%—Jetbrains Teamcity25/2/202617/6/2026
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
AnalizadaMedia (6.1)0.29%—Jetbrains Teamcity25/2/202617/6/2026
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
AnalizadaCrítica (9.8)5.7%💥 ExploitFrangoteam Fuxa24/2/202617/6/2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT…
AplazadaAlta (7.5)0.41%—Beeteam368 VidorevAI20/2/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidoRev vidorev allows PHP Local File Inclusion.This issue affects VidoRev: from n/a through <= 2.9.9.9.9.9.7.
AplazadaAlta (8.8)0.36%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI20/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.
AnalizadaAlta (7.5)0.60%—Microsoft Teams19/2/202617/6/2026
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
ModificadaMedia (5.1)0.34%—M2team Nanazip19/2/202617/6/2026
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
AnalizadaMedia (5.1)0.15%—M2team Nanazip19/2/202617/6/2026
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
AnalizadaMedia (5.2)0.16%—M2team Nanazip19/2/202617/6/2026
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0…
AplazadaMedia (5.4)0.30%—Aa-team WzoneAI19/2/202617/6/2026
Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.