Real-Time CVE Alerts & Vulnerability Tracker
Search enriched vulnerability intelligence โ EPSS exploitability scores, CVSS severity, CISA KEV status โ and get instant alerts to Slack, Telegram, Discord or Google Chat.
236,247 results
Stored XSS in Basamak Informatics' DernekWeb
Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App
Calling window.close() from server-side content causes crash in the Mattermost Desktop App
SSRF via Host Header Spoofing in Custom Slash Commands
Prevent password disclosure and force reset during Slack import
Sensitive credentials exposed in plaintext in Mattermost support packets
Slash command trigger-word update allowed command hijacking
Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooks
Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets
Missing authorization check in AI message rewrite endpoint allows access to private thread content
Instance and webhook GitLab plugin commands were able to be run by non-admin users
Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook update
Missing request origin validation on burn-on-read reveal endpoint
Code Injection in Perforce P4 (Helix Core)
Memory Exhaustion via Malicious 7zip File Upload
Incomplete group locking implementation
Group prefix matching bypass for subscriptions
Unescaped variables during error page composition
Insufficient token rotation validation in remote cluster invite confirmation
Mattermost fails to enforce create_post permission when editing posts
Never miss a critical vulnerability
Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS โ get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.
Slack ยท Telegram ยท Discord ยท Google Chat