Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1775 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.36%—Growatt Cloud Portal15/4/202517/6/2026
An attacker can export other users' plant information.
AnalizadaMedia (6.9)0.64%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
AnalizadaCrítica (9.3)0.50%—Growatt Cloud Portal15/4/202517/6/2026
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
AnalizadaMedia (6.9)0.30%—Growatt Cloud Portal15/4/202517/6/2026
An authenticated attacker can obtain any plant name by knowing the plant ID.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
AnalizadaMedia (6.9)0.31%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain a user's plant list by knowing the username.
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
AnalizadaAlta (8.7)0.39%—Growatt Cloud Portal15/4/202517/6/2026
An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value while adding or editing a plant.
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
AnalizadaMedia (6.9)0.84%—Growatt Cloud Portal15/4/202517/6/2026
An attacker can change registered email addresses of other users and take over arbitrary accounts.
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
AnalizadaMedia (5.4)0.23%—Mattermost Server14/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
AnalizadaMedia (4.3)0.25%—Mattermost Server14/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
AnalizadaMedia (4.9)0.24%—Mattermost Server14/4/202517/6/2026
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via…
AnalizadaAlta (7.5)0.27%—Mattermost Mobile14/4/202517/6/2026
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications
AnalizadaBaja (2.7)0.29%—Mattermost Server10/4/202517/6/2026
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
AplazadaAlta (7.1)0.38%—Hivedigital Canonical AttachmentsAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8.
AplazadaAlta (8.1)1.1%—Ratta Supernote A6 X2 NomadAI7/4/202517/6/2026
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.
AplazadaMedia (6.5)0.22%—Cheesefather Botnet Attack BlockerAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botnet Attack Blocker botnet-attack-blocker allows Stored XSS.This issue affects Botnet Attack Blocker: from n/a through <= 2.0.0.
AplazadaMedia (6.5)0.31%—Matthewrubin Local MagicAI3/4/202517/6/2026
Missing Authorization vulnerability in matthewrubin Local Magic local-magic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Local Magic: from n/a through <= 2.9.0.
AplazadaMedia (5.3)0.45%—Matthewrubin Review ManagerAI1/4/202517/6/2026
Missing Authorization vulnerability in matthewrubin Review Manager review-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Review Manager: from n/a through <= 2.5.0.
AplazadaMedia (6.5)0.51%—Andy Stratton Append ContentAI1/4/202517/6/2026
Missing Authorization vulnerability in Andy Stratton Append Content append-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Append Content: from n/a through <= 2.1.1.