Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.34% | — | Jetbrains Teamcity | 30/9/2026 | 2/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | |
| En análisis | Alta (8.8) | 0.46% | — | Jetbrains TeamcityAI | 30/9/2026 | 1/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | |
| En análisis | Alta (8.8) | 0.43% | — | Jetbrains TeamcityAI | 30/9/2026 | 1/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | |
| Aplazada | Alta (7) | 0.10% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in… | |
| Aplazada | Alta (8.8) | 0.38% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an… | |
| Aplazada | Alta (7.3) | 0.09% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in… | |
| Aplazada | Alta (7.8) | 0.14% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially… | |
| Aplazada | Alta (7.8) | 0.13% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the… | |
| Aplazada | Media (5.3) | 0.21% | — | Wpdarko Team MembersAI | 26/9/2026 | 29/9/2026 | The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the… | |
| Aplazada | Alta (7.1) | 0.21% | — | Openclaw MsteamsAIOpenclaw FeishuAIOpenclaw MatrixAIOpenclaw GooglechatAI | 26/9/2026 | 28/9/2026 | OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a… | |
| Aplazada | Alta (8.4) | 0.30% | — | IsteamxAI | 24/9/2026 | 25/9/2026 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to… | |
| Aplazada | Media (5.3) | 0.24% | — | TeamAI | 23/9/2026 | 23/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. | |
| Aplazada | Baja (2) | 0.19% | — | Recommenders-team RecommendersAI | 23/9/2026 | 23/9/2026 | A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (5.4) | 0.24% | — | Ninjateam FilebirdAI | 18/9/2026 | 19/9/2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.47% | — | Nextcloud Team FoldersAINextcloud WorkspaceAI | 18/9/2026 | 18/9/2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management… | |
| Aplazada | Crítica (9.1) | 0.91% | — | Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>.… | |
| Aplazada | Alta (7.2) | 0.21% | — | Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in,… | |
| Pendiente de análisis | Alta (8.6) | 0.69% | — | TeamAIAmazon IAM Identity CenterAI | 14/9/2026 | 14/9/2026 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated… | |
| Analizada | Media (6.3) | 0.32% | — | Microsoft Teams | 8/9/2026 | 29/9/2026 | Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (6.8) | 0.89% | — | Microsoft Teams | 8/9/2026 | 29/9/2026 | Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.5) | 0.38% | — | Siemens TeamcenterAI | 8/9/2026 | 9/9/2026 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute… | |
| Aplazada | Crítica (9.3) | 0.63% | — | Teampasswordmanager Team Password ManagerAI | 1/9/2026 | 23/9/2026 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. | |
| Aplazada | Alta (8.8) | 2.0% | — | Teamviewer Full ClientAITeamviewer HostAI | 26/8/2026 | 1/9/2026 | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking… | |
| Aplazada | Alta (7.5) | 0.27% | — | Teamviewer DesktopAI | 26/8/2026 | 1/9/2026 | Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to… | |
| Aplazada | Alta (7.1) | 0.44% | — | M2team NanazipAI | 20/8/2026 | 18/9/2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe even though… |