Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
–

1611 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.25%—Mattermost Server18/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints..…
AnalizadaMedia (4.8)0.24%—Mattermost Server18/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost…
AnalizadaMedia (6.5)0.24%—Mattermost Server18/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}..…
AnalizadaMedia (4.3)0.25%—Mattermost Server18/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private…
AnalizadaMedia (6.5)0.42%—Mattermost Server15/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image/png) embedded in an…
AnalizadaMedia (4.3)0.27%—Mattermost Server15/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID:…
AplazadaMedia (5.3)0.44%—Magento Long Term SupportAI15/5/202617/6/2026
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -> System -> Import/Export -> Dataflow -…
AplazadaMedia (6.1)0.24%—Magento Long Term SupportAI15/5/202617/6/2026
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, Mage_ProductAlert_AddController::stockAction() reads the uenc query parameter and passes it directly to…
AplazadaCrítica (9.3)0.49%—Magento Long Term SupportAI15/5/202617/6/2026
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, the XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a…
AnalizadaMedia (5.5)0.31%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente.
ModificadaMedia (4.3)0.70%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
ModificadaAlta (8.8)0.30%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
ModificadaAlta (7.8)0.33%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
ModificadaAlta (8.4)0.45%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+112/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente.
AnalizadaMedia (5.5)0.55%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.