vciy

CVEs we hold for Team

Records whose assigning authority named Team as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-91039dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account…team-alembic ash_authentication
CVE-2026-88952OAuth2 sign-in attached to an existing account without an email comparison in AshAuthenticationteam-alembic ash_authentication
CVE-2026-8722Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injectionsTEAM Net::Async::Statsd::Client
CVE-2026-86688Session id is not renewed on authentication in ash_authentication, allowing session fixationteam-alembic ash_authentication
CVE-2026-86533Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenixteam-alembic ash_authentication_phoenix
CVE-2026-86522Log injection via an unescaped password reset identity in AshAuthenticationteam-alembic ash_authentication
CVE-2026-85667xiaobei through 5.5.2 Unauthenticated Webhook Message InjectionTeamWiseFlow xiaobei
CVE-2026-85500`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthenticationteam-alembic ash_authentication
CVE-2026-84699Team Password Manager before 14.184.308 Authentication Bypass in Password ResetTeam Password Manager
CVE-2026-8381Broken Access Control in TeamViewer DEX Platform (On Premises)TeamViewer DEX (On-premises)
CVE-2026-82761Magic link single-use tokens replayable via TOCTOU race in AshAuthenticationteam-alembic ash_authentication
CVE-2026-82760Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-inteam-alembic ash_authentication
CVE-2026-82759Reversible IP address pseudonymisation in AshAuthentication audit log hash modeteam-alembic ash_authentication
CVE-2026-82723Actor record with password digest stored in AshAuthentication audit log entriesteam-alembic ash_authentication
CVE-2026-82685Confirmation token accepted on any record in AshAuthenticationteam-alembic ash_authentication
CVE-2026-81637Replayable OAuth2 CSRF state retained after a failed callback in AshAuthenticationteam-alembic ash_authentication
CVE-2026-81632Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenixteam-alembic ash_authentication
CVE-2026-81098Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transportteam-telnyx telnyx-mcp
CVE-2026-80218Sign-in token minted for one resource accepted by another in AshAuthenticationteam-alembic ash_authentication
CVE-2026-78223Token revocation record built from unverified JWT claims in AshAuthenticationteam-alembic ash_authentication
CVE-2026-76949Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacementteam-alembic ash_authentication
CVE-2026-7547Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameterteamwsa Woosa – Marktplaats for WooCommerce
CVE-2026-66882Reflected XSS in AshAuthentication confirmation and magic link interaction formsteam-alembic ash_authentication
CVE-2026-65633Purpose-limited JWT accepted as full bearer authentication in AshAuthenticationteam-alembic ash_authentication
CVE-2026-5967TeamT5|ThreatSonar Anti-Ransomware - Privilege EscalationTeamT5 ThreatSonar Anti-Ransomware
CVE-2026-5966TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File DeletionTeamT5 ThreatSonar Anti-Ransomware
CVE-2026-49757OAuth2/OIDC account takeover in AshAuthentication via email-based user matchingteam-alembic ash_authentication
CVE-2026-4741Path Traversal Vulnerability in TeamJCD/JoyConDroidTeamJCD JoyConDroid
CVE-2026-4392TeamSpeak 3 Server clientek Handshake assertionn/a TeamSpeak 3 Server
CVE-2026-4391TeamSpeak 3 Server ECC Key heap-based overflown/a TeamSpeak 3 Server
CVE-2026-4390TeamSpeak 3 Server Connection State Management process_resend_queue use after freen/a TeamSpeak 3 Server
CVE-2026-3107Multiple vulnerabilities in TeampassTeampass
CVE-2026-3106Multiple vulnerabilities in TeampassTeampass
CVE-2026-2695Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)TeamViewer DEX (On-Premises)
CVE-2026-23572Improper Access Control in TeamViewer clientsTeamViewer One
CVE-2026-23571Command Injection in 1E-Nomad-RunPkgStatusRequest Instruction in TeamViewer DEXTeamViewer DEX
CVE-2026-23570Log timestamp tampering vulnerability in Content Distribution ServiceTeamViewer DEX
CVE-2026-23569Out-of-bounds read vulnerability in Content Distribution ServiceTeamViewer DEX
CVE-2026-23568Out-of-bounds read vulnerability in Content Distribution ServiceTeamViewer DEX
CVE-2026-23567Integer underflow in Content Distribution Service UDP handlerTeamViewer DEX
CVE-2026-23566Log Injection in Content Distribution Service UDP HandlerTeamViewer DEX
CVE-2026-23565Denial-of-Service in Content Distribution ServiceTeamViewer DEX
CVE-2026-23564Transmission of Unencrypted Data in Content Distribution ServiceTeamViewer DEX
CVE-2026-23563Privilege escalation in TeamViewer DEX via DeleteFileByPath instructionTeamViewer DEX
CVE-2026-19042Command Injection in TeamViewer Desktop Client for Linux through Chat Link HandlingTeamViewer Host
CVE-2026-16444Improper Validation of File Paths in TeamViewer Desktop ClientsTeamViewer Full Client, Host, QuickSupport (v13 for macOS)
CVE-2026-12703Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOSTeamViewer ONE
CVE-2026-1075ZT Captcha <= 1.0.4 - Cross-Site Request Forgery to Settings Updateteamzt ZT Captcha
CVE-2025-7145TeamT5|ThreatSonar Anti-Ransomware - OS Command InjectionTeamT5 ThreatSonar Anti-Ransomware
CVE-2025-64995Privilege Escalation via Process Hijacking in 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instructionTeamViewer DEX
CVE-2025-64994Privilege Escalation via Uncontrolled Search Path in 1E-Nomad-SetWorkRate instructionTeamViewer DEX
CVE-2025-64993Command Injection in 1E-ConfigMgrConsoleExtensions InstructionsTeamViewer DEX
CVE-2025-64992Command Injection in 1E-Nomad-PauseNomadJobQueue InstructionTeamViewer DEX
CVE-2025-64991Command Injection in 1E-PatchInsights-Deploy InstructionTeamViewer DEX
CVE-2025-64990Command Injection in 1E-Explorer-TachyonCore-LogoffUser InstructionTeamViewer DEX
CVE-2025-64989Command Injection in 1E-Explorer-TachyonCore-FindFileBySizeAndHash InstructionTeamViewer DEX
CVE-2025-64988Command Injection in 1E-Nomad-GetCmContentLocations InstructionTeamViewer DEX
CVE-2025-64987Command Injection in 1E-Explorer-TachyonCore-CheckSimpleIoC InstructionTeamViewer DEX
CVE-2025-64986Command Injection in 1E-Explorer-TachyonCore-DevicesListeningOnAPort InstructionTeamViewer DEX
CVE-2025-46266Unauthenticated Transmission of Data in NomadBranch.exeTeamViewer DEX
CVE-2025-4477TeamT5 ThreatSonar Anti-Ransomware - Privilege EscalationTeamT5 ThreatSonar Anti-Ransomware
CVE-2025-44016File Hash Validation Bypass in NomadBranch.exeTeamViewer DEX
CVE-2025-44002Arbitrary File Creation via Symbolic Link leading to Denial-of-ServiceTeamViewer Host
CVE-2025-41421Privilege Escalation via Symbolic Link Spoofing in TeamViewer ClientTeamViewer Host
CVE-2025-39462WordPress Smart Agreements plugin <= 1.0.3 - Local File Inclusion vulnerabilityteamzt Smart Agreements
CVE-2025-36537Incorrect Permission Assignment for Critical Resource in TeamViewer Remote ManagementTeamViewer Host (Win7/8)
CVE-2025-32782Ash Authentication email link auto-click account confirmation vulnerabilityteam-alembic ash_authentication
CVE-2025-31831WordPress AtomChat plugin <= 1.1.7 - Broken Access Control vulnerabilityTeam AtomChat AtomChat
CVE-2025-31532WordPress AtomChat plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerabilityTeam AtomChat AtomChat
CVE-2025-25202Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`team-alembic ash_authentication
CVE-2025-14124Team < 5.0.11 - Unauthenticated SQLiUnknown Team
CVE-2025-13621dream gallery <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Actionteamdream dream gallery
CVE-2025-12687Denial-of-Service Vulnerability in NomadBranch.exeTeamViewer DEX
CVE-2025-11560Team Members Showcase < 3.5.0 - Reflected XSSUnknown Team Members Showcase
CVE-2025-0065Improper Neutralization of Argument Delimiters in TeamViewer ClientsTeamViewer Remote Host
CVE-2024-9923TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Move through Path Traversalteamplus technology team+
CVE-2024-9922TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Read through Path Traversalteamplus technology team+
CVE-2024-9921TEAMPLUS TECHNOLOGY Team+ - SQL Injectionteamplus technology team+
CVE-2024-9236Team Members Showcase < 4.4.2 - Editor+ Stored XSSUnknown Team
CVE-2024-7694TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File UploadTeamT5 ThreatSonar Anti-Ransomware
CVE-2024-7693Team Johnlong software Raiden MAILD Remote Management System - Arbitrary File Reading through Path TraversalTeam Johnlong software Raiden MAILD Remote Management System
CVE-2024-7481Improper signature verification of Printer driver installation in TeamViewer Remote ClientsTeamViewer Remote Host
CVE-2024-7479Improper signature verification of VPN driver installation in TeamViewer Remote ClientsTeamViewer Remote Host
CVE-2024-6053Improper access control in the clipboard synchronization featureTeamViewer Remote Full Client
CVE-2024-52373WordPress Devexhub Gallery plugin <= 2.0.1 - Arbitrary File Upload vulnerabilityTeam Devexhub Devexhub Gallery
CVE-2024-50703no title heldTeamPass
CVE-2024-50702no title heldTeamPass
CVE-2024-50701no title heldTeamPass
CVE-2024-35707WordPress Heateor Social Login WordPress plugin <= 1.1.32 - Cross Site Scripting (XSS) vulnerabilityTeam Heateor Heateor Social Login
CVE-2024-35706WordPress Heateor Social Login WordPress plugin <= 1.1.32 - Cross Site Scripting (XSS) vulnerabilityTeam Heateor Heateor Social Login
CVE-2024-33927WordPress Giphypress plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerabilityTeam GIPHY Giphypress
CVE-2024-33641WordPress Custom field finder plugin <= 0.3 - PHP Object Injection vulnerabilityTeam Yoast Custom field finder
CVE-2024-32876NewPipe has potential security vulnerability when importing settingsTeamNewPipe NewPipe
CVE-2024-31248WordPress All-in-One Video Gallery plugin <= 3.5.2 - Broken Access Control vulnerabilityTeam Plugins360 All-in-One Video Gallery
CVE-2024-29804WordPress Fancy Comments WordPress plugin <= 1.2.14 - Cross Site Scripting (XSS) vulnerabilityTeam Heateor Fancy Comments WordPress
CVE-2024-24712WordPress Heateor Social Login Plugin <= 1.1.30 is vulnerable to Cross Site Scripting (XSS)Team Heateor Heateor Social Login WordPress
CVE-2024-2451Improper fingerprint validation in the TeamViewer ClientTeamViewer Remote (Host)
CVE-2024-1933Improper symlink resolution in TeamViewer Remote client for macOSTeamViewer Remote Client
CVE-2024-1331Team Members < 5.3.2 - Author+ Stored XSSUnknown Team Members
CVE-2024-12363Insufficient permissions in the TeamViewer Patch & Asset Management componentTeamViewer Patch & Asset Management
CVE-2024-0819Incomplete protection of personal password settingsTeamViewer Remote Host
CVE-2023-5948Improper Authorization in teamamaze/amazefileutilitiesteamamaze/amazefileutilities
CVE-2023-46606WordPress AtomChat plugin <= 1.1.4 - Broken Access Control vulnerabilityTeam AtomChat AtomChat
CVE-2023-41866WordPress Automatic YouTube Gallery plugin <= 2.3.3 - Broken Access Control vulnerabilityTeam Plugins360 Automatic YouTube Gallery
CVE-2023-41802WordPress Super Socializer plugin <= 7.13.54 - Broken Access Control vulnerabilityTeam Heateor Super Socializer
CVE-2023-40680WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)Team Yoast Yoast SEO
CVE-2023-35882WordPress Super Socializer Plugin <= 7.13.52 is vulnerable to Cross Site Scripting (XSS)Team Heateor Super Socializer
CVE-2023-23977WordPress Heateor Social Comments Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)Team Heateor WordPress Social Comments Plugin for Vkontakte…
CVE-2023-23670WordPress Fancy Comments WordPress Plugin <= 1.2.10 is vulnerable to Cross Site Scripting (XSS)Team Heateor Fancy Comments WordPress
CVE-2023-0837no title heldTeamViewer Remote
CVE-2022-50931TeamSpeak 3.5.6 - Insecure File PermissionsTeamSpeak
CVE-2022-41676TEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server - Cross-Site ScriptingTEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server
CVE-2022-41675TEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server - Formula InjectionTEAM JOHNLONG SOFTWARE CO., LTD. MAILD Mail Server
CVE-2022-3936Team Members < 5.2.1 - Editor+ Stored XSSUnknown Team Members
CVE-2022-35221TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or Throttling-2Teamplus Pro
CVE-2022-35220TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or Throttling-1Teamplus Pro
CVE-2022-32958TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or ThrottlingTeamplus Pro (Private cloud)
CVE-2022-2557WordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and DeletionUnknown Team – WordPress Team Members Showcase Plugin
CVE-2022-23242TeamViewer Linux - Deletion command not properly executed after process crashTeamViewer for Linux
CVE-2022-1568Team Members < 5.1.1 - Admin+ Stored Cross-Site ScriptingUnknown Team Members
CVE-2022-0648Team Circle Image Slider With Lightbox < 1.0.16 - Reflected Cross-Site ScriptingUnknown Team Circle Image Slider With Lightbox
CVE-2021-35005no title heldTeamViewer
CVE-2021-34859no title heldTeamViewer
CVE-2021-34858no title heldTeamViewer
CVE-2021-24128Team Members < 5.0.4 - Authenticated Stored Cross-Site Scripting (XSS)Unknown Team Members
CVE-2016-7813no title heldTEAM DERAEMONS DERAEMON-CMS

126 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.