Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
1611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.42% | — | Mattermost Server | 17/4/2023 | 17/6/2026 | Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config). | |
| Modificada | Crítica (9.8) | 0.72% | — | Eskom EL Terminali (SU Okuma) Uygulamalarimiz | 14/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06. | |
| Modificada | Media (4.9) | 0.56% | — | Terminalfour | 12/4/2023 | 17/6/2026 | The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1. | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/4/2023 | 17/6/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 3.0% | 💥 Exploit | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/4/2023 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Media (4.8) | 0.39% | — | Linksoftwarellc WP Terms Popup | 6/4/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions. | |
| Modificada | Media (5.3) | 0.54% | — | Mattermost Server | 31/3/2023 | 17/6/2026 | Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message. | |
| Modificada | Media (5.4) | 0.45% | — | Mattermost Server | 31/3/2023 | 17/6/2026 | Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file. | |
| Modificada | Media (6.5) | 0.55% | — | Mattermost Server | 31/3/2023 | 17/6/2026 | When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients. | |
| Modificada | Media (5.4) | 0.32% | — | Mattermost Server | 31/3/2023 | 17/6/2026 | When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel. | |
| Modificada | Media (4.3) | 0.46% | — | Mattermost | 22/3/2023 | 17/6/2026 | Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner. | |
| Modificada | Media (6.1) | 0.41% | — | Mattermost Server | 15/3/2023 | 17/6/2026 | A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter. | |
| Modificada | Alta (7.8) | 0.39% | — | Microsoft 365Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607+11 | 14/3/2023 | 17/6/2026 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 2.5% | 💥 Exploit | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+2 | 14/3/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.1) | 0.62% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/3/2023 | 17/6/2026 | Microsoft Excel Spoofing Vulnerability | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 PoC | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 14/3/2023 | 17/6/2026 | Microsoft Outlook Elevation of Privilege Vulnerability | |
| Modificada | Baja (2.7) | 0.53% | — | Mattermost Server | 27/2/2023 | 17/6/2026 | Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response. | |
| Modificada | Baja (2.7) | 0.53% | — | Mattermost Server | 27/2/2023 | 17/6/2026 | Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response. | |
| Modificada | Media (6.5) | 0.50% | — | Mattermost | 27/2/2023 | 17/6/2026 | A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API. | |
| Modificada | Media (6.5) | 0.50% | — | Mattermost | 27/2/2023 | 17/6/2026 | A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of. | |
| Modificada | Media (6.3) | 0.31% | — | Eternal Terminal Project Eternal Terminal | 16/2/2023 | 17/6/2026 | In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file. | |
| Modificada | Crítica (9.8) | 85% | 💥 PoC | Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+4 | 14/2/2023 | 19/8/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/2/2023 | 19/8/2026 | Microsoft Office Information Disclosure Vulnerability | |
| Modificada | Crítica (9.8) | 0.86% | — | Electerm Project Electerm | 20/1/2023 | 17/6/2026 | Se descubrió un problema en Electerm 1.3.22 que permite a los atacantes ejecutar código arbitrario mediante una solicitud no verificada al servicio electerms. | |
| Modificada | Media (5.3) | 1.1% | — | Eternal Terminal Project Eternal Terminal | 13/1/2023 | 17/6/2026 | En Eternal Terminal 6.2.1, etserver y etclient tienen archivos de registro legibles en todo el mundo. |