Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
485 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.83% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph. | |
| Modificada | Media (4.3) | 0.58% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry. | |
| Modificada | Media (4.3) | 0.74% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled. | |
| Modificada | Media (5.3) | 0.92% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled. | |
| Modificada | Media (5.4) | 0.79% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy. | |
| Modificada | Media (5.3) | 0.77% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed. | |
| Modificada | Alta (8.8) | 0.93% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text. | |
| Modificada | Media (4.3) | 0.58% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges. | |
| Modificada | Baja (2.7) | 0.74% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy. | |
| Modificada | Media (5.3) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel. | |
| Modificada | Alta (7.5) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command. | |
| Modificada | Media (5.3) | 0.81% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API. | |
| Modificada | Media (4.3) | 0.58% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel. | |
| Modificada | Media (4.3) | 0.61% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command. | |
| Modificada | Media (4.3) | 0.58% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body. | |
| Modificada | Media (6.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions. | |
| Modificada | Baja (3.7) | 0.73% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing. | |
| Modificada | Alta (7.5) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page. | |
| Modificada | Media (4.9) | 0.87% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file. | |
| Modificada | Media (4.9) | 0.73% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name. |