Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Openclaw MsteamsAIOpenclaw FeishuAIOpenclaw MatrixAIOpenclaw GooglechatAI | 26/9/2026 | 28/9/2026 | OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a… | |
| Aplazada | Alta (8.4) | 0.30% | — | IsteamxAI | 24/9/2026 | 25/9/2026 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to… | |
| Aplazada | Media (6.5) | 0.23% | — | Omnipressteam OmnipressAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.6.7. | |
| Aplazada | Alta (7.5) | 0.45% | — | Omnipressteam OmnipressAIPHPAI | 23/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File Inclusion.This issue affects Omnipress: from n/a through <= 1.6.7. | |
| Aplazada | Media (6.4) | 0.36% | — | Omnipressteam OmnipressAI | 5/12/2025 | 25/9/2026 | The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Aplazada | Media (6.5) | 0.23% | — | Omnipressteam OmnipressAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows DOM-Based XSS.This issue affects Omnipress: from n/a through <= 1.6.4. | |
| Aplazada | Alta (8.4) | 0.20% | — | Valve SteamAI | 21/5/2025 | 17/6/2026 | An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL. | |
| Analizada | Media (6.5) | 0.27% | — | Omnipressteam Omnipress | 14/3/2025 | 17/6/2026 | The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from… | |
| Aplazada | Alta (7.1) | 0.29% | — | Omnipressteam OmnipressAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.4.3. | |
| Modificada | Media (5.3) | 0.57% | — | Jenkins Msteams Webhook Trigger | 25/10/2023 | 17/6/2026 | Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (6.8) | 0.99% | — | Archisteamfarm Project Archisteamfarm | 8/2/2022 | 17/6/2026 | ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like… | |
| Modificada | Alta (7.5) | 1.0% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. A broken access control vulnerability has been found while… | |
| Modificada | Media (5.3) | 0.79% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the identification of the correct tenant for… | |
| Modificada | Media (5.3) | 0.79% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given… | |
| Modificada | Alta (8.8) | 1.0% | — | Dalmark Systeam Enterprise Resource Planning | 21/12/2021 | 17/6/2026 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. The bi report module exposes direct SQL… | |
| Modificada | Media (5.4) | 0.62% | — | Steam Group Viewer Project Steam Group Viewer | 2/8/2021 | 17/6/2026 | The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (5.9) | 1.7% | — | Archisteamfarm Project Archisteamfarm | 26/7/2021 | 17/6/2026 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In versions prior to 4.3.1.0 a Denial of Service (aka DoS) vulnerability which allows attacker to remotely crash running ASF instance through sending a specifically-crafted Steam chat message exists.… | |
| Modificada | Alta (7.5) | 1.0% | — | Archisteamfarm Project Archisteamfarm | 26/7/2021 | 17/6/2026 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `IPCPassword` from the resulting config when the caller did not specify it… | |
| Modificada | Crítica (9) | 3.5% | — | Valvesoftware Steam Client | 10/4/2021 | 17/6/2026 | Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click. | |
| Modificada | Alta (7.8) | 0.55% | — | Valvesoftware Steam Client | 5/7/2020 | 17/6/2026 | An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMFILES(X86)%\Steam have weak permissions during a critical time window. An attacker can make this time window arbitrarily… | |
| Modificada | Alta (7.8) | 0.72% | — | Valvesoftware Steam Client | 4/10/2019 | 17/6/2026 | Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or unspecified other impact. | |
| Modificada | Alta (7) | 0.45% | — | Valvesoftware Steam Client | 21/8/2019 | 17/6/2026 | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition. | |
| Modificada | Alta (7.8) | 0.41% | — | Valvesoftware Steam Client | 21/8/2019 | 17/6/2026 | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch. | |
| Modificada | Media (6.6) | 0.62% | — | Valvesoftware Steam Client | 7/8/2019 | 17/6/2026 | In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access. | |
| Modificada | Media (5.4) | 0.89% | — | Valvesoftware Steam Client | 20/5/2019 | 17/6/2026 | In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites. |