Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.21% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission to create posts to cause excessive server CPU consumption and degrade… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than intended and block the indexing of other files… | |
| Pendiente de análisis | Media (5.3) | 0.25% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plugin process and deny calendar integration service to all users on the… | |
| Pendiente de análisis | Media (5) | 0.13% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpoint.. Mattermost Advisory ID: MMSA-2026-00692 | |
| Analizada | Media (6.5) | 0.37% | — | Mattermost Server | 14/9/2026 | 6/10/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-management access to crash the Playbooks plugin via a REST request referencing… | |
| Aplazada | Baja (1.9) | 0.17% | — | Matthiaswandel JheadAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The… | |
| Aplazada | Baja (1.9) | 0.16% | — | Matthiaswandel JheadAI | 14/9/2026 | 14/9/2026 | A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The… | |
| Aplazada | Media (5.4) | 0.33% | — | Rattler CacheAIPY RattlerAI | 9/9/2026 | 10/9/2026 | Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache`… | |
| Analizada | Media (6.6) | 0.27% | — | Google Go-attestation | 8/9/2026 | 24/9/2026 | An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation sub-event without enforcing a maximum… | |
| Aplazada | Alta (7.5) | 0.46% | — | Automattic WoocommerceAI | 8/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0. | |
| Aplazada | Baja (2) | 0.33% | — | Projectwolds Online Attendance SystemAI | 6/9/2026 | 8/9/2026 | A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public… | |
| Aplazada | Alta (7.6) | 0.40% | — | Automattic WoocommerceAI | 4/9/2026 | 4/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0. | |
| Aplazada | Alta (7.5) | 0.42% | — | Appchee Woocommerce Product AttachmentAI | 2/9/2026 | 2/9/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | |
| Aplazada | Baja (3.7) | 0.26% | — | Limitloginattempts Limit Login Attempts ReloadedAI | 21/8/2026 | 26/8/2026 | The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Attack Analyzer Connector FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in… | |
| Aplazada | Alta (8.8) | 0.33% | — | Mattrobenolt Flask PrincipalAINetflix LemurAIPalletsprojects FlaskAI | 18/8/2026 | 16/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unset because both flags default to False.… | |
| Analizada | Baja (3.5) | 0.27% | — | Mattermost Server | 17/8/2026 | 19/8/2026 | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads… | |
| Analizada | Baja (3.3) | 0.13% | — | Mattermost Desktop | 17/8/2026 | 19/8/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity… | |
| Analizada | Media (6.5) | 0.34% | — | Mattermost Server | 17/8/2026 | 19/8/2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID:… | |
| Analizada | Alta (8.3) | 0.35% | — | Mattermost Server | 17/8/2026 | 19/8/2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST… | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Server | 17/8/2026 | 18/8/2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SUBSCRIBE_TEAM message with a non-string teamId.. Mattermost Advisory… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | MattermostAIMattermost Gitlab PluginAI | 17/8/2026 | 18/8/2026 | Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to… | |
| Analizada | Media (6.3) | 0.26% | — | Mattermost Server | 17/8/2026 | 18/8/2026 | Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697 | |
| Analizada | Media (4.3) | 0.27% | — | Mattermost Server | 17/8/2026 | 18/8/2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the membership of private channels on the same team via creating, patching, importing, or bulk-creating… | |
| Analizada | Media (4.3) | 0.25% | — | Mattermost Server | 17/8/2026 | 18/8/2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost… |