863 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-1768
Devolutions Server General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

CVE-2026-2461
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-639 1 PoC

Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559

CVE-2026-26246
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-789 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00572

CVE-2026-2458
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-2025-00568

CVE-2026-2687
Reading progressbar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-3115
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594

CVE-2026-0997
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558

CVE-2026-0554
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset analytics for any NotificationX campaign, regardless of ownership.

CVE-2026-22916
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.

CVE-2026-3927
Chrome General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-22918
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-1021 1 PoC

An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

CVE-2026-22915
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-497 1 PoC

An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.

CVE-2026-24692
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554

CVE-2026-1747
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

CVE-2026-1629
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-672 1 PoC

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580

CVE-2026-44919
Ironic General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-696 1 PoC

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

CVE-2026-3925
Chrome General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-0602
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in the snippet rendering process under certain circumstances.

CVE-2026-1508
Court Reservation Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2026-20719
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-754 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595