Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3) | 0.18% | — | Mattermost Server | 17/12/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts. | |
| Aplazada | Media (4.3) | 0.22% | — | Ryanpcmcquen Import External AttachmentsAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in ryanpcmcquen Import external attachments import-external-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Import external attachments: from n/a through <= 1.5.12. | |
| Aplazada | Media (4.3) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 16/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Cross Site Request Forgery.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Simple Attendance Record System | 14/12/2025 | 7/10/2026 | A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing manipulation of the argument student results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Alta (8.6) | 0.32% | — | Growatt Shine Lan-x Firmware | 13/12/2025 | 7/10/2026 | The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device | |
| Analizada | Crítica (9.4) | 0.32% | — | Growatt Shine Lan-x Firmware | 13/12/2025 | 7/10/2026 | Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X… | |
| Aplazada | Crítica (9.4) | 0.07% | — | Growatt Shinelan-xAIGrowatt MIC 3300tl-xAI | 13/12/2025 | 7/10/2026 | Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint. | |
| Analizada | Alta (8.6) | 0.16% | — | Growatt Shine Lan-x Firmware | 13/12/2025 | 7/10/2026 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code. | |
| Analizada | Alta (8.4) | 0.16% | — | Growatt Shine Lan-x Firmware | 13/12/2025 | 7/10/2026 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code. | |
| Analizada | Crítica (9.4) | 0.32% | — | Growatt Shine Lan-x Firmware | 13/12/2025 | 7/10/2026 | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature… | |
| Aplazada | Media (6.4) | 0.24% | — | List Attachments ShortcodeAI | 6/12/2025 | 17/6/2026 | The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' parameter in the [list-attachments] shortcode in all versions up to, and including, 0.4.1a due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.22% | — | Mattermost Server | 2/12/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to | |
| Analizada | Media (4.3) | 0.18% | — | Mattermost Server | 1/12/2025 | 17/6/2026 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users. | |
| Analizada | Crítica (9.9) | 0.34% | — | Mattermost Server | 27/11/2025 | 17/6/2026 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when… | |
| Analizada | Media (4.3) | 0.22% | — | Mattermost Server | 27/11/2025 | 17/6/2026 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint | |
| Analizada | Crítica (9.9) | 0.34% | — | Mattermost Server | 27/11/2025 | 17/6/2026 | Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data… | |
| Aplazada | Crítica (10) | 0.93% | — | Md-to-pdfAIGray-matterAI | 21/11/2025 | 17/6/2026 | md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library,… | |
| Aplazada | Media (6.8) | 0.27% | — | Attention BARAI | 20/11/2025 | 17/6/2026 | The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such as administrator to perform SQL injection attacks | |
| Analizada | Baja (3.5) | 0.17% | — | Mattermost Server | 18/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects | |
| Analizada | Alta (7.3) | 0.45% | — | Silentmatt Javascript Expression Evaluator | 14/11/2025 | 7/10/2026 | npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue. | |
| Analizada | Media (4.9) | 0.28% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint | |
| Analizada | Media (5.3) | 0.18% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL. | |
| Analizada | Alta (7.5) | 0.30% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events | |
| Analizada | Media (4.3) | 0.17% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads | |
| Analizada | Media (4.3) | 0.19% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint |