Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2022-32227
A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "v…
Rocket.chat
4.7.5 / 4.8.2+
MEDIUM 5.3
CVE-2022-32217
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.
Rocket.chat
4.6.4+
MEDIUM 6.1
CVE-2022-21830
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their cha…
Livechat
1.9.0+
MEDIUM 6.1
CVE-2020-8291
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
Rocket.chat
3.9.0+
MEDIUM 6.5
CVE-2021-32832
Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and …
Rocket.chat
3.11.3 / 3.12.2+
CRITICAL 9.8
CVE-2021-22910
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result i…
Rocket.chat
3.11.4 / 3.12.4+
HIGH 7.5
CVE-2020-26763
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
Rocket.chat
Patch available
CRITICAL 9.8
CVE-2021-22911EPSS 95%
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, result…
Rocket.chat
No fix yet
HIGH 7.5
CVE-2021-22892
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed …
Rocket.chat
3.11.3 / 3.12.2+
MEDIUM 6.1
CVE-2021-22886
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote att…
Rocket.chat
3.8.8 / 3.9.7+
MEDIUM 5.4
CVE-2020-8288
The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parame…
Rocket.chat
3.9.2+
MEDIUM 5.4
CVE-2020-8292
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
Rocket.chat
3.9.0+
MEDIUM 5.3
CVE-2020-28208EPSS 11%
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
Rocket.chat
after 3.9.1
CRITICAL 9.8
CVE-2020-29594
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.
Rocket.chat
0.74.4 / 1.3.4+
MEDIUM 6.1
CVE-2020-15926
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which r…
Rocket.chat
after 3.4.2
MEDIUM 6.1
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
Rocket.chat
2.1.0+
MEDIUM 6.1
CVE-2018-13878
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescape…
Rocket.chat
0.65+
MEDIUM 5.4
CVE-2018-13879
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a u…
Rocket.chat
0.66+
CRITICAL 9.8
CVE-2017-1000493
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
Rocket.chat
after 0.59