863 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-3925
Chrome General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-20719
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-754 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595

CVE-2026-22912
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-601 1 PoC

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

CVE-2026-2272
Red Hat Enterprise Linux 6 General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-190 1 PoC

A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation, allowing oversized image headers to bypass security checks. A remote attacker could exploit this by providing a specially crafted ICO file, leading to a buffer overflow and memory corruption, which may result in an application level denial of service.

CVE-2026-25780
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-789 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581

CVE-2026-1369
Conditional CAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2026-25783
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-1287 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586

CVE-2026-31150
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources.

CVE-2026-1230
GitLab DevOps
4.1
MEDIUM
EPSS
0.1%
2026 CWE-706 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVE-2026-33555
HAProxy Web
4.0
MEDIUM
EPSS
0.0%
2026 CWE-130 1 PoC

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

CVE-2026-41254
little cms color engine Web
4.0
MEDIUM
EPSS
0.0%
2026 CWE-696 2 PoCs

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVE-2026-42798
little cms color engine Web
4.0
MEDIUM
EPSS
0.0%
2026 CWE-190 1 PoC

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

CVE-2026-3634
Red Hat Enterprise Linux 10 Web
3.9
LOW
EPSS
0.0%
2026 CWE-93 1 PoC

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

CVE-2026-26230
Mattermost Web
3.8
LOW
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MMSA-2025-00531

CVE-2026-22919
TDC-X401GL Web
3.8
LOW
EPSS
0.0%
2026 CWE-79 1 PoC

An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.

CVE-2026-24661
Mattermost General
3.7
LOW
EPSS
0.0%
2026 CWE-770 1 PoC

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

CVE-2026-22885
SmartServer IoT General
3.7
LOW
EPSS
0.1%
2026 CWE-125 2 PoCs

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.

CVE-2026-3832
Software Genérico General
3.7
LOW
EPSS
0.0%
2026 CWE-179 1 PoC

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

CVE-2026-21388
Mattermost General
3.7
LOW
EPSS
0.0%
2026 CWE-770 1 PoC

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

CVE-2026-22920
TDC-X401GL General
3.7
LOW
EPSS
0.0%
2026 CWE-1391 1 PoC

The device's passwords have not been adequately salted, making them vulnerable to password extraction attacks.