Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
485 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.63% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview. | |
| Modificada | Media (5.3) | 0.81% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file. | |
| Modificada | Crítica (9.1) | 0.67% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server. | |
| Modificada | Media (4.3) | 0.58% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links. | |
| Modificada | Alta (7.5) | 0.66% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file. | |
| Modificada | Alta (8.8) | 0.43% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled. | |
| Modificada | Media (5.3) | 0.93% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints. | |
| Modificada | Media (5.3) | 0.93% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document. | |
| Modificada | Crítica (9.8) | 1.3% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report. | |
| Modificada | Media (5.3) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. | |
| Modificada | Media (5.3) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection. | |
| Modificada | Media (5.3) | 0.78% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint. | |
| Modificada | Media (5.3) | 0.93% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint. | |
| Modificada | Alta (8.1) | 0.83% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link. | |
| Modificada | Media (4.3) | 0.78% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request. | |
| Modificada | Media (4.3) | 0.67% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts. |