Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Ixray-team Ixray-1.6-stcopAI | 24/3/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Analizada | Media (4.3) | 0.18% | — | Mattermost MS Teams | 16/3/2026 | 17/6/2026 | Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606 | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (5.3) | 0.26% | — | Radiustheme Tlp-teamAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13. | |
| Aplazada | Alta (7.5) | 0.51% | — | Magepeopleteam WpbookinglyAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly service-booking-manager allows PHP Local File Inclusion.This issue affects WpBookingly: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.5) | 0.51% | — | Redqteam Turbo ManagerAIPHPAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8. | |
| Aplazada | Media (5.3) | 0.33% | — | Magepeopleteam WpeventlyAIMagepeopleteam Mage-eventpressAI | 13/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retrieve Embedded Sensitive Data.This issue affects WpEvently: from n/a through < 5.1.9. | |
| Aplazada | Alta (7.1) | 0.46% | — | 2-plan TeamAI | 6/3/2026 | 17/6/2026 | 2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executable PHP files by sending multipart form data to managefile.php. Attackers can upload PHP files through the userfile1 parameter with action=upload, which are stored in the files directory and executed… | |
| Analizada | Alta (7.8) | 0.18% | — | Natroteam Natro Macro | 6/3/2026 | 17/6/2026 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code contained inside of a pattern or path file is executed by the macro. Since users commonly share path/pattern files, an attacker could share a file containing malicious code, which is then executed by the… | |
| Analizada | Alta (8) | 0.35% | — | Natroteam Natro Macro | 6/3/2026 | 17/6/2026 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-private channel gives access to any user with the permission to send message in said channel access to do anything on their computer. This includes keyboard and… | |
| Aplazada | Alta (8.1) | 0.52% | — | Ancorathemes FixteamAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes FixTeam fixteam allows PHP Local File Inclusion.This issue affects FixTeam: from n/a through <= 1.5.0. | |
| Analizada | Media (5.1) | 0.16% | — | M2team Nanazip | 26/2/2026 | 17/6/2026 | NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory access during archive open/listing. The bug is reachable via normal… | |
| Analizada | Media (5.1) | 0.14% | — | M2team Nanazip | 26/2/2026 | 17/6/2026 | NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer underflow in header-size calculation and trigger an unbounded memory… | |
| Analizada | Media (5.1) | 0.16% | — | M2team Nanazip | 26/2/2026 | 17/6/2026 | NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulnerability in manifest parsing. A crafted bundle can provide a malformed `RelativePathLength` so the parser constructs a… | |
| Analizada | Baja (2.3) | 0.17% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | |
| Analizada | Media (4.3) | 0.26% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | |
| Analizada | Media (6.1) | 0.29% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow | |
| Analizada | Crítica (9.8) | 5.7% | 💥 Exploit | Frangoteam Fuxa | 24/2/2026 | 17/6/2026 | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT… | |
| Aplazada | Alta (7.5) | 0.41% | — | Beeteam368 VidorevAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidoRev vidorev allows PHP Local File Inclusion.This issue affects VidoRev: from n/a through <= 2.9.9.9.9.9.7. | |
| Aplazada | Alta (8.8) | 0.36% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9. | |
| Analizada | Alta (7.5) | 0.60% | — | Microsoft Teams | 19/2/2026 | 17/6/2026 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Media (5.1) | 0.34% | — | M2team Nanazip | 19/2/2026 | 17/6/2026 | NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue. | |
| Analizada | Media (5.1) | 0.15% | — | M2team Nanazip | 19/2/2026 | 17/6/2026 | NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue. | |
| Analizada | Media (5.2) | 0.16% | — | M2team Nanazip | 19/2/2026 | 17/6/2026 | NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0… | |
| Aplazada | Media (5.4) | 0.30% | — | Aa-team WzoneAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31. |