CVEs we hold for Team
Records whose assigning authority named Team as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-91039dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account…team-alembic ash_authentication
CVE-2026-88952OAuth2 sign-in attached to an existing account without an email comparison in AshAuthenticationteam-alembic ash_authentication
CVE-2026-8722Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injectionsTEAM Net::Async::Statsd::Client
CVE-2026-86688Session id is not renewed on authentication in ash_authentication, allowing session fixationteam-alembic ash_authentication
CVE-2026-86533Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenixteam-alembic ash_authentication_phoenix
CVE-2026-86522Log injection via an unescaped password reset identity in AshAuthenticationteam-alembic ash_authentication
CVE-2026-85500`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthenticationteam-alembic ash_authentication
CVE-2026-84699Team Password Manager before 14.184.308 Authentication Bypass in Password ResetTeam Password Manager
CVE-2026-8381Broken Access Control in TeamViewer DEX Platform (On Premises)TeamViewer DEX (On-premises)
CVE-2026-82761Magic link single-use tokens replayable via TOCTOU race in AshAuthenticationteam-alembic ash_authentication
CVE-2026-82760Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-inteam-alembic ash_authentication
CVE-2026-82759Reversible IP address pseudonymisation in AshAuthentication audit log hash modeteam-alembic ash_authentication
CVE-2026-82723Actor record with password digest stored in AshAuthentication audit log entriesteam-alembic ash_authentication
CVE-2026-82685Confirmation token accepted on any record in AshAuthenticationteam-alembic ash_authentication
CVE-2026-81637Replayable OAuth2 CSRF state retained after a failed callback in AshAuthenticationteam-alembic ash_authentication
CVE-2026-81632Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenixteam-alembic ash_authentication
CVE-2026-81098Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transportteam-telnyx telnyx-mcp
CVE-2026-80218Sign-in token minted for one resource accepted by another in AshAuthenticationteam-alembic ash_authentication
CVE-2026-78223Token revocation record built from unverified JWT claims in AshAuthenticationteam-alembic ash_authentication
CVE-2026-76949Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacementteam-alembic ash_authentication
CVE-2026-7547Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameterteamwsa Woosa – Marktplaats for WooCommerce
CVE-2026-66882Reflected XSS in AshAuthentication confirmation and magic link interaction formsteam-alembic ash_authentication
CVE-2026-65633Purpose-limited JWT accepted as full bearer authentication in AshAuthenticationteam-alembic ash_authentication
CVE-2026-5967TeamT5|ThreatSonar Anti-Ransomware - Privilege EscalationTeamT5 ThreatSonar Anti-Ransomware
CVE-2026-5966TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File DeletionTeamT5 ThreatSonar Anti-Ransomware
CVE-2026-49757OAuth2/OIDC account takeover in AshAuthentication via email-based user matchingteam-alembic ash_authentication
CVE-2026-4390TeamSpeak 3 Server Connection State Management process_resend_queue use after freen/a TeamSpeak 3 Server
CVE-2026-2695Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)TeamViewer DEX (On-Premises)
CVE-2026-23571Command Injection in 1E-Nomad-RunPkgStatusRequest Instruction in TeamViewer DEXTeamViewer DEX
CVE-2026-19042Command Injection in TeamViewer Desktop Client for Linux through Chat Link HandlingTeamViewer Host
CVE-2026-16444Improper Validation of File Paths in TeamViewer Desktop ClientsTeamViewer Full Client, Host, QuickSupport (v13 for macOS)
CVE-2026-12703Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOSTeamViewer ONE
CVE-2025-7145TeamT5|ThreatSonar Anti-Ransomware - OS Command InjectionTeamT5 ThreatSonar Anti-Ransomware
CVE-2025-64995Privilege Escalation via Process Hijacking in 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instructionTeamViewer DEX
CVE-2025-64994Privilege Escalation via Uncontrolled Search Path in 1E-Nomad-SetWorkRate instructionTeamViewer DEX
CVE-2025-64989Command Injection in 1E-Explorer-TachyonCore-FindFileBySizeAndHash InstructionTeamViewer DEX
CVE-2025-64986Command Injection in 1E-Explorer-TachyonCore-DevicesListeningOnAPort InstructionTeamViewer DEX
CVE-2025-4477TeamT5 ThreatSonar Anti-Ransomware - Privilege EscalationTeamT5 ThreatSonar Anti-Ransomware
CVE-2025-39462WordPress Smart Agreements plugin <= 1.0.3 - Local File Inclusion vulnerabilityteamzt Smart Agreements
CVE-2025-36537Incorrect Permission Assignment for Critical Resource in TeamViewer Remote ManagementTeamViewer Host (Win7/8)
CVE-2025-32782Ash Authentication email link auto-click account confirmation vulnerabilityteam-alembic ash_authentication
CVE-2025-31831WordPress AtomChat plugin <= 1.1.7 - Broken Access Control vulnerabilityTeam AtomChat AtomChat
CVE-2025-31532WordPress AtomChat plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerabilityTeam AtomChat AtomChat
CVE-2025-25202Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`team-alembic ash_authentication
CVE-2025-13621dream gallery <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Actionteamdream dream gallery
CVE-2025-0065Improper Neutralization of Argument Delimiters in TeamViewer ClientsTeamViewer Remote Host
CVE-2024-9923TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Move through Path Traversalteamplus technology team+
CVE-2024-9922TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Read through Path Traversalteamplus technology team+
CVE-2024-7694TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File UploadTeamT5 ThreatSonar Anti-Ransomware
CVE-2024-7693Team Johnlong software Raiden MAILD Remote Management System - Arbitrary File Reading through Path TraversalTeam Johnlong software Raiden MAILD Remote Management System
CVE-2024-7481Improper signature verification of Printer driver installation in TeamViewer Remote ClientsTeamViewer Remote Host
CVE-2024-7479Improper signature verification of VPN driver installation in TeamViewer Remote ClientsTeamViewer Remote Host
CVE-2024-6053Improper access control in the clipboard synchronization featureTeamViewer Remote Full Client
CVE-2024-52373WordPress Devexhub Gallery plugin <= 2.0.1 - Arbitrary File Upload vulnerabilityTeam Devexhub Devexhub Gallery
CVE-2024-35707WordPress Heateor Social Login WordPress plugin <= 1.1.32 - Cross Site Scripting (XSS) vulnerabilityTeam Heateor Heateor Social Login
CVE-2024-35706WordPress Heateor Social Login WordPress plugin <= 1.1.32 - Cross Site Scripting (XSS) vulnerabilityTeam Heateor Heateor Social Login
CVE-2024-33927WordPress Giphypress plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerabilityTeam GIPHY Giphypress
CVE-2024-33641WordPress Custom field finder plugin <= 0.3 - PHP Object Injection vulnerabilityTeam Yoast Custom field finder
CVE-2024-32876NewPipe has potential security vulnerability when importing settingsTeamNewPipe NewPipe
CVE-2024-31248WordPress All-in-One Video Gallery plugin <= 3.5.2 - Broken Access Control vulnerabilityTeam Plugins360 All-in-One Video Gallery
CVE-2024-29804WordPress Fancy Comments WordPress plugin <= 1.2.14 - Cross Site Scripting (XSS) vulnerabilityTeam Heateor Fancy Comments WordPress
CVE-2024-24712WordPress Heateor Social Login Plugin <= 1.1.30 is vulnerable to Cross Site Scripting (XSS)Team Heateor Heateor Social Login WordPress
CVE-2024-1933Improper symlink resolution in TeamViewer Remote client for macOSTeamViewer Remote Client
CVE-2024-12363Insufficient permissions in the TeamViewer Patch & Asset Management componentTeamViewer Patch & Asset Management
CVE-2023-46606WordPress AtomChat plugin <= 1.1.4 - Broken Access Control vulnerabilityTeam AtomChat AtomChat
CVE-2023-41866WordPress Automatic YouTube Gallery plugin <= 2.3.3 - Broken Access Control vulnerabilityTeam Plugins360 Automatic YouTube Gallery
CVE-2023-41802WordPress Super Socializer plugin <= 7.13.54 - Broken Access Control vulnerabilityTeam Heateor Super Socializer
CVE-2023-40680WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)Team Yoast Yoast SEO
CVE-2023-35882WordPress Super Socializer Plugin <= 7.13.52 is vulnerable to Cross Site Scripting (XSS)Team Heateor Super Socializer
CVE-2023-23977WordPress Heateor Social Comments Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)Team Heateor WordPress Social Comments Plugin for Vkontakte…
CVE-2023-23670WordPress Fancy Comments WordPress Plugin <= 1.2.10 is vulnerable to Cross Site Scripting (XSS)Team Heateor Fancy Comments WordPress
CVE-2022-41676TEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server - Cross-Site ScriptingTEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server
CVE-2022-41675TEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server - Formula InjectionTEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server
CVE-2022-35221TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or Throttling-2Teamplus Pro
CVE-2022-35220TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or Throttling-1Teamplus Pro
CVE-2022-32958TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or ThrottlingTeamplus Pro (Private cloud)
CVE-2022-2557WordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and DeletionUnknown Team – WordPress Team Members Showcase Plugin
CVE-2022-23242TeamViewer Linux - Deletion command not properly executed after process crashTeamViewer for Linux
CVE-2022-0648Team Circle Image Slider With Lightbox < 1.0.16 - Reflected Cross-Site ScriptingUnknown Team Circle Image Slider With Lightbox
CVE-2021-24128Team Members < 5.0.4 - Authenticated Stored Cross-Site Scripting (XSS)Unknown Team Members
126 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.