832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-4989
Server Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-918 1 PoC

Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 2026.1.11, from 2025.3.1 through 2025.3.17.

CVE-2026-3942
Chrome General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-0929
RegistrationMagic Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

CVE-2026-25780
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-789 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581

CVE-2026-0998
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and post data.. Mattermost Advisory ID: MMSA-2025-00534

CVE-2026-2455
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-918 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 literals (e.g., [::ffff:127.0.0.1]).. Mattermost Advisory ID: MMSA-2026-00585

CVE-2026-22918
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-1021 1 PoC

An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

CVE-2026-1508
Court Reservation Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2026-20719
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-754 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595

CVE-2026-2272
Red Hat Enterprise Linux 6 General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-190 1 PoC

A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation, allowing oversized image headers to bypass security checks. A remote attacker could exploit this by providing a specially crafted ICO file, leading to a buffer overflow and memory corruption, which may result in an application level denial of service.

CVE-2026-2463
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565

CVE-2026-22646
Incoming Goods Suite General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-209 1 PoC

Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.

CVE-2026-2458
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-2025-00568

CVE-2026-3115
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594

CVE-2026-2457
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-346 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MMSA-2025-00569

CVE-2026-22914
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

CVE-2026-25916
Webmail General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-420 1 PoC

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

CVE-2026-21386
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-203 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588

CVE-2026-1128
WP eCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could allow attackers to make a logged in admin remove them via a CSRF attack

CVE-2026-22913
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.