Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.30% | — | Mattermost Server | 21/8/2025 | 17/6/2026 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbitrary filesystem… | |
| Analizada | Media (4.3) | 0.22% | — | Mattermost Server | 21/8/2025 | 17/6/2026 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id. | |
| Analizada | Baja (3.5) | 0.19% | — | Mattermost Server | 21/8/2025 | 17/6/2026 | Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions | |
| Analizada | Media (4.9) | 0.49% | — | Mattermost Server | 21/8/2025 | 17/6/2026 | Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature… | |
| Aplazada | Alta (8.4) | 0.49% | 💥 Exploit | Lattice Semiconductor Ispvm SystemAI | 13/8/2025 | 16/6/2026 | Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project files. When parsing the version attribute of the ispXCF XML tag, the application fails to properly validate input length, allowing a specially crafted file to overwrite memory on the stack. This can… | |
| Analizada | Media (5.3) | 0.20% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint. | |
| Analizada | Alta (7.5) | 0.34% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body. | |
| Analizada | Media (5.3) | 0.24% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint. | |
| Analizada | Alta (7.5) | 0.30% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. | |
| Analizada | Media (5) | 0.21% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint. | |
| Analizada | Media (4) | 0.20% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint. | |
| Analizada | Baja (3.7) | 0.21% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint. | |
| Analizada | Media (5.9) | 0.29% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body. | |
| Analizada | Alta (7.5) | 0.34% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body. | |
| Analizada | Baja (3.7) | 0.25% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint. | |
| Analizada | Media (6.4) | 0.18% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint. | |
| Analizada | Alta (7.2) | 0.21% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint. | |
| Analizada | Media (4) | 0.21% | — | Mattermost Confluence | 11/8/2025 | 17/6/2026 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters. | |
| Analizada | Media (6.1) | 0.20% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php. | |
| Aplazada | Crítica (9.8) | 0.66% | 💥 PoC | Bayraktar Solar Energies Scadawatt OtopilotAI | 24/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection. This issue affects ScadaWatt Otopilot: before 27.05.2025. |