Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
485 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.62% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case. | |
| Modificada | Alta (7.5) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change. | |
| Modificada | Media (6.5) | 0.93% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation. | |
| Modificada | Media (5.5) | 0.31% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking. | |
| Modificada | Media (4.3) | 0.70% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID. | |
| Modificada | Media (5.3) | 0.81% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel. | |
| Modificada | Alta (7.5) | 0.94% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. | |
| Modificada | Media (5.3) | 0.81% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post. | |
| Modificada | Media (5.3) | 0.92% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled. | |
| Modificada | Alta (8.8) | 0.49% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF. | |
| Modificada | Alta (7.5) | 0.94% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. | |
| Modificada | Alta (7.5) | 0.94% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands. | |
| Modificada | Media (5.5) | 0.87% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document. | |
| Modificada | Alta (7.5) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters. | |
| Modificada | Alta (7.5) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration. | |
| Modificada | Alta (7.5) | 1.3% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message. | |
| Modificada | Media (6.5) | 0.79% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001. | |
| Modificada | Alta (7.5) | 0.94% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004. | |
| Modificada | Media (5.3) | 0.92% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012. | |
| Modificada | Alta (7.5) | 0.64% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005. | |
| Modificada | Media (5.3) | 1.3% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014. |