Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.29% | — | Joinmastodon Mastodon | 21/10/2025 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and 4.5.0-beta.2. Mastodon internally treats reblogs as… | |
| Analizada | Media (4.3) | 0.27% | — | Joinmastodon Mastodon | 13/10/2025 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those tokens lack the read:statuses scope. This allows OAuth clients… | |
| Analizada | Media (4.3) | 0.23% | — | Joinmastodon Mastodon | 13/10/2025 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receiving real-time updates through existing… | |
| Analizada | Baja (3.5) | 0.21% | — | Joinmastodon Mastodon | 13/10/2025 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions and access tokens for that account are… | |
| Analizada | Alta (7.5) | 0.56% | — | Joinmastodon Mastodon | 6/8/2025 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting system has a critical configuration error where the email-based throttle… | |
| Aplazada | Media (6.5) | 0.25% | — | Wolfgang Include Mastodon FeedAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed include-mastodon-feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: from n/a through <= 1.9.9. | |
| Analizada | Media (5.3) | 0.36% | — | Joinmastodon Mastodon | 27/2/2025 | 17/6/2026 | Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reasons. Instance admins that do not want… | |
| Analizada | Media (5.3) | 0.37% | — | Joinmastodon Mastodon | 27/2/2025 | 17/6/2026 | Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the… | |
| Aplazada | Media (6.4) | 0.40% | — | Include Mastodon FeedAI | 21/11/2024 | 17/6/2026 | The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.5) | 0.47% | — | Joinmastodon Mastodon | 18/11/2024 | 17/6/2026 | Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header. | |
| Analizada | Media (5.9) | 0.38% | — | Joinmastodon Mastodon | 3/10/2024 | 17/6/2026 | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header. | |
| Analizada | Alta (8.2) | 0.53% | — | Joinmastodon Mastodon | 5/7/2024 | 17/6/2026 | Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining access to the contents of a post not… | |
| Analizada | Alta (7.7) | 0.51% | — | Joinmastodon Mastodon | 19/2/2024 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat… | |
| Analizada | Media (4.3) | 0.36% | — | Joinmastodon Mastodon | 14/2/2024 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application to continue listening to streaming… | |
| Analizada | Alta (7.4) | 0.47% | — | Joinmastodon Mastodon | 14/2/2024 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This results in a possible account takeover if the authentication provider allows… | |
| Modificada | Crítica (9.8) | 2.5% | — | Joinmastodon Mastodon | 1/2/2024 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x… | |
| Modificada | Media (5.4) | 0.44% | — | Joinmastodon Mastodon | 19/9/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing unescaped HTML to execute in the browser.… | |
| Modificada | Alta (7.5) | 0.67% | — | Joinmastodon Mastodon | 19/9/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for… | |
| Modificada | Alta (7.5) | 0.46% | — | Joinmastodon Mastodon | 19/9/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon. This can be used to perform confused deputy attacks if the server… | |
| Modificada | Media (5.4) | 0.62% | — | Joinmastodon Mastodon | 6/7/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of the link, enabling it to appear to link to a different URL… | |
| Modificada | Alta (7.5) | 1.3% | — | Joinmastodon Mastodon | 6/7/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations. Prior to versions 3.5.9, 4.0.5, and 4.1.3, a malicious server can indefinitely extend the duration of the response through slowloris-type attacks.… | |
| Modificada | Crítica (9.9) | 40% | — | Joinmastodon Mastodon | 6/7/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and… | |
| Modificada | Media (6.1) | 1.2% | — | Joinmastodon Mastodon | 6/7/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. This introduces a… | |
| Modificada | Media (6.5) | 1.3% | — | Joinmastodon Mastodon | 4/4/2023 | 17/6/2026 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary… | |
| Modificada | Media (4.3) | 0.69% | — | Joinmastodon Mastodon | 6/3/2023 | 17/6/2026 | The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the appeal of a user whose status update was marked as sensitive. |