Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

1611 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.42%—Mattermost Server17/4/202317/6/2026
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).
ModificadaCrítica (9.8)0.72%—Eskom EL Terminali (SU Okuma) Uygulamalarimiz14/4/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06.
ModificadaMedia (4.9)0.56%—Terminalfour12/4/202317/6/2026
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
ModificadaAlta (7.8)2.7%💥 ExploitMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel11/4/202317/6/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (7.8)3.0%💥 ExploitMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel11/4/202317/6/2026
Microsoft Office Remote Code Execution Vulnerability
ModificadaMedia (4.8)0.39%—Linksoftwarellc WP Terms Popup6/4/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
ModificadaMedia (5.3)0.54%—Mattermost Server31/3/202317/6/2026
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
ModificadaMedia (5.4)0.45%—Mattermost Server31/3/202317/6/2026
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
ModificadaMedia (6.5)0.55%—Mattermost Server31/3/202317/6/2026
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
ModificadaMedia (5.4)0.32%—Mattermost Server31/3/202317/6/2026
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
ModificadaMedia (4.3)0.46%—Mattermost22/3/202317/6/2026
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
ModificadaMedia (6.1)0.41%—Mattermost Server15/3/202317/6/2026
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
ModificadaAlta (7.8)0.39%—Microsoft 365Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607+1114/3/202317/6/2026
Windows Graphics Component Elevation of Privilege Vulnerability
ModificadaAlta (7.8)2.5%💥 ExploitMicrosoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+214/3/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.1)0.62%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/3/202317/6/2026
Microsoft Excel Spoofing Vulnerability
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 PoCMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook14/3/202317/6/2026
Microsoft Outlook Elevation of Privilege Vulnerability
ModificadaBaja (2.7)0.53%—Mattermost Server27/2/202317/6/2026
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
ModificadaBaja (2.7)0.53%—Mattermost Server27/2/202317/6/2026
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
ModificadaMedia (6.5)0.50%—Mattermost27/2/202317/6/2026
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
ModificadaMedia (6.5)0.50%—Mattermost27/2/202317/6/2026
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
ModificadaMedia (6.3)0.31%—Eternal Terminal Project Eternal Terminal16/2/202317/6/2026
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
ModificadaCrítica (9.8)85%💥 PoCMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+414/2/202319/8/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel14/2/202319/8/2026
Microsoft Office Information Disclosure Vulnerability
ModificadaCrítica (9.8)0.86%—Electerm Project Electerm20/1/202317/6/2026
Se descubrió un problema en Electerm 1.3.22 que permite a los atacantes ejecutar código arbitrario mediante una solicitud no verificada al servicio electerms.
ModificadaMedia (5.3)1.1%—Eternal Terminal Project Eternal Terminal13/1/202317/6/2026
En Eternal Terminal 6.2.1, etserver y etclient tienen archivos de registro legibles en todo el mundo.
Orbitaley — Vulnerabilidades