Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.90%—Rocket.chat26/1/202117/6/2026
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
ModificadaMedia (5.4)0.85%—Rocket.chat26/1/202117/6/2026
The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.
ModificadaMedia (5.3)11%💥 ExploitRocket.chat8/1/202117/6/2026
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
ModificadaCrítica (9.8)1.6%—Rocket.chat30/12/202017/6/2026
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.
ModificadaMedia (6.1)2.8%—Rocket.chat18/8/202017/6/2026
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
ModificadaMedia (6.1)4.0%💥 ExploitRocket.chat21/10/201917/6/2026
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
ModificadaMedia (5.4)0.62%—Rocket.chat11/7/201817/6/2026
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via…
ModificadaMedia (6.1)0.76%—Rocket.chat11/7/201817/6/2026
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins…
ModificadaCrítica (9.8)1.7%—Rocket.chat3/1/201817/6/2026
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
ModificadaMedia (6.1)0.73%—Rocketchat Rocket.chat17/7/201717/6/2026
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
Orbitaley — Vulnerabilidades