Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

485 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.81%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
ModificadaCrítica (9.8)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
ModificadaAlta (8.1)0.79%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
ModificadaMedia (5.3)0.78%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
ModificadaMedia (6.1)0.34%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
ModificadaMedia (4.3)0.75%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
ModificadaMedia (4.3)0.66%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
ModificadaMedia (6.5)0.94%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
ModificadaBaja (2.7)0.63%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
ModificadaMedia (5.3)0.88%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
ModificadaMedia (5.3)0.93%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
ModificadaCrítica (9.8)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
ModificadaMedia (6.5)0.73%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
ModificadaMedia (5.4)0.56%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
ModificadaAlta (7.5)0.90%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
ModificadaMedia (5.3)0.93%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
ModificadaMedia (5.3)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
ModificadaAlta (7.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
Orbitaley — Vulnerabilidades