Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Openclaw MsteamsAIOpenclaw FeishuAIOpenclaw MatrixAIOpenclaw GooglechatAI | 26/9/2026 | 28/9/2026 | OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a… | |
| Analizada | Media (6.3) | 0.32% | — | Microsoft Teams | 8/9/2026 | 29/9/2026 | Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (6.8) | 0.89% | — | Microsoft Teams | 8/9/2026 | 29/9/2026 | Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Teams | 11/8/2026 | 16/8/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.94% | — | Microsoft Teams | 11/8/2026 | 14/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.6) | 0.61% | — | Microsoft Teams | 11/8/2026 | 16/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Teams | 7/8/2026 | 11/8/2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.50% | — | Microsoft Teams | 7/8/2026 | 7/8/2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Teams | 7/8/2026 | 7/8/2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Baja (2.3) | 0.26% | — | Openclaw MS TeamsAI | 17/7/2026 | 17/7/2026 | OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature. | |
| Analizada | Alta (8.1) | 1.2% | — | Microsoft Teams | 9/6/2026 | 23/7/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | |
| Aplazada | Alta (7) | 0.66% | — | NanobotAIMicrosoft TeamsAIMicrosoft BOT FrameworkAI | 1/6/2026 | 22/7/2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation… | |
| Aplazada | Media (6.9) | 0.64% | — | Teamspeak 3 ServerAI | 27/5/2026 | 17/6/2026 | A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the component clientek Handshake Handler. Performing a manipulation of the argument proof results in reachable assertion. Remote exploitation of the attack is possible. Upgrading to version 3.13.8 is capable… | |
| Aplazada | Media (6.9) | 0.69% | — | Teamspeak 3 ServerAI | 27/5/2026 | 17/6/2026 | A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such manipulation leads to heap-based buffer overflow. The attack may be launched remotely. Upgrading to version 3.13.8 is able to resolve this issue. It is suggested… | |
| Aplazada | Media (5.3) | 0.41% | — | Teamspeak 3 ServerAI | 27/5/2026 | 17/6/2026 | A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation causes use after free. The attack may be initiated remotely. Upgrading to version 3.13.8 is able to mitigate this issue. The affected… | |
| Analizada | Media (5.5) | 0.55% | — | Microsoft Teams | 12/5/2026 | 17/6/2026 | Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Media (6.5) | 0.86% | — | Microsoft Teams | 7/5/2026 | 17/6/2026 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (4.3) | 0.18% | — | Mattermost MS Teams | 16/3/2026 | 17/6/2026 | Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606 | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.60% | — | Microsoft Teams | 19/2/2026 | 17/6/2026 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (8.5) | 0.23% | — | Teamspeak | 13/1/2026 | 17/6/2026 | TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or Administrator-level access. | |
| Aplazada | Media (5.3) | 0.25% | — | Malwarebytes FOR TeamsAI | 24/10/2025 | 17/6/2026 | In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mbamservice.exe. | |
| Analizada | Alta (7.5) | 0.81% | — | Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+1 | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.19% | — | Microsoft Teams | 8/7/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. | |
| Analizada | Baja (3.1) | 0.43% | — | Microsoft Teams | 8/7/2025 | 17/6/2026 | Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |