Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.81% | — | Catia Magic Collaboration StudioAI3DS Teamwork CloudAI | 1/6/2026 | 22/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution. | |
| Analizada | Media (5.3) | 0.28% | — | Wimi-teamwork | 8/4/2026 | 24/7/2026 | Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other users' private or… | |
| Analizada | Baja (2.1) | 0.40% | — | Xiweicheng Teamwork Management System | 17/1/2026 | 17/6/2026 | A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Xiweicheng Teamwork Management System | 17/1/2026 | 17/6/2026 | A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unrestricted upload. The attack may be performed from remote. The exploit is now… | |
| Analizada | Baja (1.9) | 0.28% | — | Xiweicheng Teamwork Management System | 17/12/2025 | 17/6/2026 | A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be… | |
| Aplazada | Alta (7) | 0.25% | — | Open LAB TeamworkAI | 27/10/2025 | 17/6/2026 | Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a JSON field named 'csrf_token' without validating the field’s value; only the presence of the field is checked. An attacker can craft a cross-site… | |
| Modificada | Media (6.1) | 0.51% | — | Teamwork Management System Project Teamwork Management System | 4/1/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function. | |
| Modificada | Alta (7.5) | 0.20% | — | 3DS Teamwork Cloud NO Magic Release | 9/10/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server. | |
| Modificada | Media (5.4) | 0.34% | — | 3DS Teamwork Cloud NO Magic Release | 13/9/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code. | |
| Modificada | Media (5.9) | 0.75% | — | Teamwork Management System Project Teamwork Management System | 20/3/2022 | 17/6/2026 | TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password. | |
| Modificada | Alta (7.8) | 0.55% | — | 3DS Teamwork Cloud | 28/12/2020 | 17/6/2026 | An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arbitrary code as root. During installation, the user is instructed to set the system enviroment file with world writable permissions (0777 /etc/environment). Any local… | |
| Modificada | Alta (8.8) | 3.5% | — | Teamworktec Ticketplus | 28/9/2017 | 17/6/2026 | TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. | |
| Modificada | Alta (8.8) | 3.5% | — | Teamworktec Photo Fusion | 28/9/2017 | 17/6/2026 | TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. | |
| Modificada | Alta (8.8) | 3.5% | — | Teamworktec JOB Links | 28/9/2017 | 17/6/2026 | TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. | |
| Modificada | Media (4.3) | 1.3% | — | Alcatel-lucent Omnitouch 8400 Instant Communications SuiteAlcatel-lucent Omnitouch 8460 Advanced Communication ServerAlcatel-lucent Omnitouch 8660 MY TeamworkAlcatel-lucent Omnitouch 8670 Automated Delivery Message Delivery System | 20/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant… | |
| Modificada | Alta (10) | 1.4% | — | Open LAB Teamwork | 20/12/2005 | 16/6/2026 | Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug." |