Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

485 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.62%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
ModificadaAlta (7.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
ModificadaMedia (6.5)0.93%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation.
ModificadaMedia (5.5)0.31%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.
ModificadaMedia (4.3)0.70%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited flag after changing a post's file ID.
ModificadaMedia (5.3)0.81%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.
ModificadaAlta (7.5)0.94%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
ModificadaMedia (5.3)0.81%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.
ModificadaMedia (5.3)0.92%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled.
ModificadaAlta (8.8)0.49%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.
ModificadaAlta (7.5)0.94%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
ModificadaAlta (7.5)0.94%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
ModificadaMedia (5.5)0.87%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.
ModificadaAlta (7.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters.
ModificadaAlta (7.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
ModificadaAlta (7.5)1.3%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.
ModificadaMedia (6.5)0.79%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
ModificadaAlta (7.5)0.94%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.
ModificadaMedia (5.3)0.92%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012.
ModificadaAlta (7.5)0.64%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
ModificadaMedia (5.3)1.3%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
Orbitaley — Vulnerabilidades