Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.64% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 9/12/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.64% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 9/12/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.56% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/12/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.66% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7) | 0.52% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 9/12/2025 | 7/10/2026 | Uso después de liberar en Microsoft Office Word permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 7/10/2026 | Acceso a un recurso utilizando un tipo incompatible ('confusión de tipos') en Microsoft Office permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 7/10/2026 | Salto de ruta relativo en Microsoft Office Access permite a un atacante no autorizado ejecutar código localmente. | |
| Aplazada | Alta (7.1) | 0.15% | — | Valentin Agachi Create Posts AND TermsAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Valentin Agachi Create Posts & Terms create-posts-terms permite XSS Almacenado. Este problema afecta a Create Posts & Terms: desde n/d hasta menor o igual a 1.3.1. | |
| Analizada | Crítica (9.8) | 0.34% | — | Terminalfour | 2/12/2025 | 17/6/2026 | In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged… | |
| Analizada | Media (4.3) | 0.22% | — | Mattermost Server | 2/12/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to | |
| Analizada | Media (4.3) | 0.18% | — | Mattermost Server | 1/12/2025 | 17/6/2026 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users. | |
| Analizada | Crítica (9.9) | 0.34% | — | Mattermost Server | 27/11/2025 | 17/6/2026 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when… | |
| Analizada | Media (4.3) | 0.22% | — | Mattermost Server | 27/11/2025 | 17/6/2026 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint | |
| Analizada | Crítica (9.9) | 0.34% | — | Mattermost Server | 27/11/2025 | 17/6/2026 | Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data… | |
| Aplazada | Media (4.3) | 0.12% | — | Igor Jerosimic I Order TermsAI | 21/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Igor Jerosimić I Order Terms i-order-terms allows Cross Site Request Forgery.This issue affects I Order Terms: from n/a through <= 1.5.0. | |
| Analizada | Baja (3.5) | 0.17% | — | Mattermost Server | 18/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects | |
| Analizada | Media (4.9) | 0.28% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint | |
| Analizada | Media (5.3) | 0.18% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL. | |
| Analizada | Alta (7.5) | 0.30% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events | |
| Analizada | Media (4.3) | 0.17% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads | |
| Analizada | Media (4.3) | 0.19% | — | Mattermost Server | 14/11/2025 | 17/6/2026 | Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint | |
| Analizada | Media (6.5) | 0.14% | — | Mattermost Mobile | 13/11/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses | |
| Analizada | Media (4.3) | 0.18% | — | Mattermost Server | 13/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint | |
| Analizada | Alta (7.8) | 0.41% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |