Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.7) | 0.37% | — | Csa-iot Matter | 14/7/2026 | 5/10/2026 | A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer before dereferencing. A remote… | |
| Analizada | Media (5.7) | 0.28% | — | Csa-iot Matter | 14/7/2026 | 5/10/2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a write of OperationMode=2 (in the Pump Configuration and Control cluster), the server… | |
| Analizada | Media (5.7) | 0.29% | — | Csa-iot Matter | 14/7/2026 | 5/10/2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is executed and followed by a conflicting write to the OperationMode attribute (in… | |
| Pendiente de análisis | Alta (7.6) | 0.56% | — | SAP Change AND Transport System Attach ToolAI | 14/7/2026 | 14/7/2026 | SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim… | |
| Aplazada | Media (5.3) | 0.16% | — | FlashattentionAI | 13/7/2026 | 17/9/2026 | FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache… | |
| Analizada | Media (4.3) | 0.27% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command… | |
| Analizada | Baja (3.8) | 0.26% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost… | |
| Analizada | Media (4.3) | 0.25% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID.… | |
| Analizada | Media (4.9) | 0.36% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming… | |
| Analizada | Media (5.4) | 0.23% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory… | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Server | 13/7/2026 | 15/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint..… | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers… | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a… | |
| Analizada | Media (4.3) | 0.24% | — | Mattermost Server | 13/7/2026 | 14/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs… | |
| Analizada | Media (5.4) | 0.29% | — | Mattermost Server | 13/7/2026 | 14/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel… | |
| Aplazada | Media (5.1) | 0.33% | — | Akpali9 Attendance-management-systemAI | 12/7/2026 | 13/7/2026 | A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date results in cross site scripting. It is possible to initiate the attack remotely.… | |
| Pendiente de análisis | Media (5.9) | 0.33% | — | Drupal RAW FormatterAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. | |
| Pendiente de análisis | Media (5.9) | 0.31% | — | Drupal Brute Force Attack ProtectionAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. | |
| Analizada | Alta (8.1) | 0.43% | — | Flag Attendance Field Project Flag Attendance Field | 10/7/2026 | 14/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. | |
| Analizada | Media (5.4) | 0.23% | — | Ademarco UI Patterns | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17. | |
| Analizada | Crítica (9.8) | 0.56% | — | Zroger Formatter Field | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. | |
| Aplazada | Media (5.5) | 0.12% | — | ChatterbotAI | 9/7/2026 | 9/7/2026 | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create pattern followed by tar.extractall(path=self.data_path), allowing a local… | |
| Aplazada | Media (4.3) | 0.14% | — | WerkstattAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions. | |
| Aplazada | Media (4.3) | 0.27% | — | WerkstattAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | PerfmattersAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions. |