Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1775 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.40%—Mattermost Server24/4/202517/6/2026
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the…
AplazadaCrítica (9.3)0.37%—Matthewrubin Local MagicAI17/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic local-magic allows SQL Injection.This issue affects Local Magic: from n/a through <= 2.9.0.
AnalizadaMedia (4.3)0.28%—Mattermost Server16/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.
AplazadaMedia (6.5)0.35%—Sukimalab Attendance ManagerAI16/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tnomi Attendance Manager attendance-manager allows Stored XSS.This issue affects Attendance Manager: from n/a through <= 0.6.2.
AnalizadaMedia (6.5)0.28%—Mattermost Server16/4/202517/6/2026
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.
AnalizadaMedia (5.9)0.34%—Mattermost ServerMattermost MS Teams16/4/202517/6/2026
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret…
AnalizadaMedia (4.3)0.27%—Mattermost Server16/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to access such information when a channel is archived.
AnalizadaBaja (2.7)0.24%—Mattermost Server16/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
AnalizadaMedia (4.3)0.22%—Mattermost Server16/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provided both the AI and…
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain EV charger energy consumption information of other users.
AnalizadaMedia (6.9)0.58%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain other users' charger information.
AnalizadaMedia (6.9)0.30%—Growatt Cloud Portal15/4/202517/6/2026
An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
AnalizadaMedia (6.9)0.54%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
AnalizadaMedia (6.9)0.64%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).
AnalizadaCrítica (9.3)0.26%—Growatt Cloud Portal15/4/202517/6/2026
An attacker can upload an arbitrary file instead of a plant image.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
AnalizadaMedia (6.9)0.58%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can query an API endpoint and get device details.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.
AnalizadaMedia (6.9)0.29%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.
AnalizadaMedia (6.9)0.29%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can rename "rooms" of arbitrary users.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can hijack other users' devices and potentially control them.