Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

485 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)0.83%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
ModificadaMedia (4.3)0.58%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
ModificadaMedia (4.3)0.74%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
ModificadaMedia (5.3)0.92%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
ModificadaMedia (5.4)0.79%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
ModificadaMedia (5.3)0.77%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
ModificadaAlta (8.8)0.93%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.
ModificadaMedia (4.3)0.58%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.
ModificadaBaja (2.7)0.74%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.
ModificadaMedia (5.3)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
ModificadaAlta (7.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
ModificadaMedia (5.3)0.81%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
ModificadaMedia (4.3)0.58%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.
ModificadaMedia (4.3)0.61%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.
ModificadaMedia (4.3)0.58%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
ModificadaCrítica (9.8)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
ModificadaMedia (6.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.
ModificadaBaja (3.7)0.73%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
ModificadaAlta (7.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
ModificadaMedia (4.9)0.87%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
ModificadaMedia (4.9)0.73%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.