431 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-1628
Mattermost General
4.6
MEDIUM
EPSS
0.0%
2026 CWE-829 1 PoC

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596

CVE-2026-21736
Graphics DDK General
4.4
MEDIUM
EPSS
0.0%
2026 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.

CVE-2026-28418
vim General
4.4
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue.

CVE-2026-28420
vim General
4.4
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.

CVE-2026-42140
macro-plantuml General
4.4
MEDIUM
EPSS
0.0%
2026 CWE-918 1 PoC

PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro is vulnerable to Server-Side Request Forgery (SSRF). The macro allows users to specify an alternative PlantUML server via the server parameter. However, the application does not validate the supplied URL. An attacker can supply an internal IP address or a malicious external URL. The XWiki server will attempt to connect to this URL to "render" the diagram. This issue has been patched in version 2.4.1.

CVE-2026-22914
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

CVE-2026-22917
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

CVE-2026-25916
Webmail General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-420 1 PoC

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

CVE-2026-21386
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-203 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588

CVE-2026-2463
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565

CVE-2026-2578
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-201 1 PoC

Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

CVE-2026-22646
Incoming Goods Suite General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-209 1 PoC

Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.

CVE-2026-2455
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-918 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 literals (e.g., [::ffff:127.0.0.1]).. Mattermost Advisory ID: MMSA-2026-00585

CVE-2026-22913
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.

CVE-2026-4265
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553

CVE-2026-1768
Devolutions Server General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

CVE-2026-2461
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-639 1 PoC

Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559

CVE-2026-26246
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-789 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00572

CVE-2026-3115
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594

CVE-2026-22916
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.