Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | WerkstattAI | 2/7/2026 | 2/7/2026 | Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. | |
| Aplazada | Alta (7.5) | 0.94% | — | PerfmattersAI | 2/7/2026 | 2/7/2026 | The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the… | |
| Aplazada | Alta (8.4) | 0.18% | — | AttrAI | 29/6/2026 | 11/9/2026 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr… | |
| Aplazada | Media (4.3) | 0.29% | — | Matteo Manna Simple User AvatarAI | 29/6/2026 | 8/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9. | |
| Pendiente de análisis | Media (6.8) | 0.46% | — | MattermostAI | 26/6/2026 | 26/6/2026 | Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during… | |
| Aplazada | Alta (7.1) | 0.25% | — | PerfmattersAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. | |
| Analizada | Media (6.5) | 0.14% | — | Mattermost Server | 26/6/2026 | 29/6/2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate… | |
| Analizada | Baja (3.5) | 0.27% | — | Mattermost Server | 26/6/2026 | 29/6/2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image syntax into tool result content… | |
| Pendiente de análisis | Media (5.4) | 0.29% | — | MattermostAI | 26/6/2026 | 26/6/2026 | The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID:… | |
| Analizada | Media (4.3) | 0.20% | — | Mattermost Google Drive | 25/6/2026 | 11/8/2026 | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | |
| Pendiente de análisis | Alta (8.9) | 0.27% | — | Google Go-attestationAI | 24/6/2026 | 25/6/2026 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted… | |
| Analizada | Baja (3.8) | 0.32% | — | Mattermost Server | 22/6/2026 | 26/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669 | |
| Analizada | Media (4.3) | 0.33% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain authenticated and continue receiving… | |
| Analizada | Baja (3.8) | 0.32% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint..… | |
| Analizada | Media (6.4) | 0.30% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret and disrupt the Jira integration via POST to /ac/installed during the pending-install… | |
| Analizada | Media (6.4) | 0.24% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscription before applying edits which allows an authenticated attacker to hijack subscriptions from channels they have no access to via a crafted PUT request to the… | |
| Analizada | Media (5.4) | 0.29% | — | Mattermost Server | 22/6/2026 | 23/6/2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler, which allows any authenticated user to overwrite the global default GitLab instance configuration… | |
| Aplazada | Alta (8.1) | 0.44% | — | ZermattAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions. | |
| Aplazada | Alta (7.6) | 0.31% | — | Sukimalab Attendance ManagerAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions. | |
| Analizada | Media (6.5) | 0.36% | — | Mattermost Desktop | 15/6/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-00652 | |
| Analizada | Alta (7.7) | 0.32% | — | Mattermost Desktop | 15/6/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external… | |
| Aplazada | Baja (2) | 0.21% | — | Codeastro Student Attendance Management SystemAI | 13/6/2026 | 23/7/2026 | A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now… | |
| Analizada | Alta (8.8) | 0.42% | — | Mattermost Server | 12/6/2026 | 18/6/2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group… | |
| Analizada | Media (6.5) | 0.44% | — | Mattermost Server | 12/6/2026 | 18/6/2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster… | |
| Analizada | Alta (7.6) | 0.45% | — | Mattermost Server | 12/6/2026 | 18/6/2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary locations within the target… |