Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.5)——Jetbrains TeamcityAI6/10/20266/10/2026
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
RecibidaAlta (8.8)——Jetbrains TeamcityAI6/10/20266/10/2026
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
AplazadaCrítica (9.8)0.15%—WookteamAI5/10/20266/10/2026
WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An…
AplazadaSin puntuar0.21%—WookteamAI5/10/20266/10/2026
WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file)…
AnalizadaCrítica (9.8)0.35%—Jetbrains Teamcity30/9/20262/10/2026
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
AnalizadaAlta (8.8)0.46%—Jetbrains Teamcity30/9/20266/10/2026
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
AnalizadaAlta (8.8)0.43%—Jetbrains Teamcity30/9/20266/10/2026
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
AplazadaAlta (7)0.10%—TeamviewerAI29/9/202630/9/2026
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in…
AplazadaAlta (8.8)0.38%—TeamviewerAI29/9/202630/9/2026
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an…
AplazadaAlta (7.3)0.09%—TeamviewerAI29/9/202630/9/2026
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in…
AplazadaAlta (7.8)0.14%—TeamviewerAI29/9/202630/9/2026
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially…
AplazadaAlta (7.8)0.13%—TeamviewerAI29/9/202630/9/2026
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the…
AplazadaMedia (5.3)0.21%—Wpdarko Team MembersAI26/9/202629/9/2026
The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the…
AplazadaAlta (7.1)0.21%—Openclaw MsteamsAIOpenclaw FeishuAIOpenclaw MatrixAIOpenclaw GooglechatAI26/9/202628/9/2026
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a…
AplazadaAlta (8.4)0.30%—IsteamxAI24/9/202625/9/2026
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to…
AplazadaMedia (5.3)0.24%—TeamAI23/9/202623/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
AplazadaBaja (2)0.19%—Recommenders-team RecommendersAI23/9/202623/9/2026
A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The…
AplazadaMedia (5.4)0.24%—Ninjateam FilebirdAI18/9/202619/9/2026
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.47%—Nextcloud Team FoldersAINextcloud WorkspaceAI18/9/202618/9/2026
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management…
AplazadaCrítica (9.1)0.91%—Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI17/9/202618/9/2026
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>.…
AplazadaAlta (7.2)0.21%—Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI17/9/202618/9/2026
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in,…
Pendiente de análisisAlta (8.6)0.69%—TeamAIAmazon IAM Identity CenterAI14/9/202614/9/2026
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated…
AnalizadaMedia (6.3)0.32%—Microsoft Teams8/9/202629/9/2026
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.8)0.89%—Microsoft Teams8/9/202629/9/2026
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
AplazadaAlta (8.5)0.38%—Siemens TeamcenterAI8/9/20269/9/2026
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute…