Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1773 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.11% | — | PaymatticAI | 28/9/2026 | 28/9/2026 | The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it. | |
| Aplazada | Alta (8.4) | 0.40% | — | Rattadan CosmowarpAI | 25/9/2026 | 30/9/2026 | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Smart Attendance System With QR Code ScannerAI | 23/9/2026 | 23/9/2026 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | MattermostAI | 22/9/2026 | 23/9/2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin… | |
| Pendiente de análisis | Media (5.5) | 0.26% | — | MattermostAI | 22/9/2026 | 23/9/2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal network addresses and read the responses via the configured OAuth… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | MattermostAI | 22/9/2026 | 22/9/2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load via a crafted request to {{POST /api/v4/posts/ids/reactions}}..… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Gray-matterAI | 21/9/2026 | 22/9/2026 | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution. | |
| Aplazada | Media (5.5) | 0.11% | — | Matter Project ChipAIMatter Standard SpecificationAI | 21/9/2026 | 24/9/2026 | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component | |
| Aplazada | Baja (2) | 0.40% | — | Codeastro QR Code Attendance Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be… | |
| Pendiente de análisis | Baja (2.6) | 0.22% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:… | |
| Pendiente de análisis | Baja (3.7) | 0.13% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall… | |
| Pendiente de análisis | Media (4.7) | 0.15% | — | Mattermost Desktop APPAI | 16/9/2026 | 17/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email,… | |
| Pendiente de análisis | Media (6.8) | 0.28% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaustion) via a crafted post containing deeply nested blockquotes or list… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701 | |
| Pendiente de análisis | Media (5.5) | 0.26% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT /api/v4/access_control_policies request with an… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | MattermostAIMattermost PlaybooksAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-management access to crash the Playbooks plugin via a REST request referencing… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID:… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size.. Mattermost Advisory ID: MMSA-2026-00643 | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted… | |
| Pendiente de análisis | Media (4.3) | 0.15% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints.. Mattermost Advisory ID: MMSA-2026-00715 | |
| Pendiente de análisis | Media (4.3) | 0.15% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plugin worker and trigger a denial of service via a child block whose… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | MattermostAI | 14/9/2026 | 16/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission to create posts to cause excessive server CPU consumption and degrade… |