Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.81%—Catia Magic Collaboration StudioAI3DS Teamwork CloudAI1/6/202622/7/2026
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.
AnalizadaMedia (5.3)0.28%—Wimi-teamwork8/4/202624/7/2026
Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other users' private or…
AnalizadaBaja (2.1)0.40%—Xiweicheng Teamwork Management System17/1/202617/6/2026
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used.
AnalizadaBaja (2.1)0.40%—Xiweicheng Teamwork Management System17/1/202617/6/2026
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unrestricted upload. The attack may be performed from remote. The exploit is now…
AnalizadaBaja (1.9)0.28%—Xiweicheng Teamwork Management System17/12/202517/6/2026
A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be…
AplazadaAlta (7)0.25%—Open LAB TeamworkAI27/10/202517/6/2026
Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a JSON field named 'csrf_token' without validating the field’s value; only the presence of the field is checked. An attacker can craft a cross-site…
ModificadaMedia (6.1)0.51%—Teamwork Management System Project Teamwork Management System4/1/202417/6/2026
Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function.
ModificadaAlta (7.5)0.20%—3DS Teamwork Cloud NO Magic Release9/10/202317/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.
ModificadaMedia (5.4)0.34%—3DS Teamwork Cloud NO Magic Release13/9/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.
ModificadaMedia (5.9)0.75%—Teamwork Management System Project Teamwork Management System20/3/202217/6/2026
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.
ModificadaAlta (7.8)0.55%—3DS Teamwork Cloud28/12/202017/6/2026
An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arbitrary code as root. During installation, the user is instructed to set the system enviroment file with world writable permissions (0777 /etc/environment). Any local…
ModificadaAlta (8.8)3.5%—Teamworktec Ticketplus28/9/201717/6/2026
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
ModificadaAlta (8.8)3.5%—Teamworktec Photo Fusion28/9/201717/6/2026
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
ModificadaAlta (8.8)3.5%—Teamworktec JOB Links28/9/201717/6/2026
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
ModificadaMedia (4.3)1.3%—Alcatel-lucent Omnitouch 8400 Instant Communications SuiteAlcatel-lucent Omnitouch 8460 Advanced Communication ServerAlcatel-lucent Omnitouch 8660 MY TeamworkAlcatel-lucent Omnitouch 8670 Automated Delivery Message Delivery System20/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant…
ModificadaAlta (10)1.4%—Open LAB Teamwork20/12/200516/6/2026
Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."