İçeriğe atla
Noroxi

Rocket.Chat kayıtları

rocket.chat üreticisine ait 64 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
5
Düzeltme kaydı olan
%18,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

64 kayıt
  • CVE-2021-22911
    68Bu hafta

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio

    KritikCVSS 9,8Kavram kanıtıEPSS %95

    rocket.chat · rocket.chat27 May 2021

  • CVE-2021-22910
    40Planlayın

    A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could

    KritikCVSS 9,8İstismar yokEPSS %2

    rocket.chat · rocket.chat9 Ağu 2021

  • CVE-2017-1000493
    40Planlayın

    Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

    KritikCVSS 9,8İstismar yokEPSS %2

    rocket.chat · rocket.chat2 Oca 2018

  • CVE-2022-44567
    39İzleyin

    A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternal

    KritikCVSS 9,8İstismar yokEPSS %2

    rocket.chat · rocket.chat23 Ara 2022

  • CVE-2020-29594
    39İzleyin

    Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML

    KritikCVSS 9,8İstismar yokEPSS %2

    rocket.chat · rocket.chat30 Ara 2020

  • CVE-2023-28316
    39İzleyin

    A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not i

    KritikCVSS 9,8İstismar yokEPSS %1

    rocket.chat · rocket.chat9 May 2023

  • CVE-2026-29198
    39İzleyin

    In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account t

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    rocket.chat · rocket.chat22 Nis 2026

  • CVE-2026-58066
    39İzleyin

    Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did n

    KritikCVSS 9,8İstismar yokEPSS %0

    rocket.chat · rocket.chat30 Tem 2026

  • CVE-2026-28514
    37İzleyin

    Rocket.Chat: Users can login with any password via the EE ddp-streamer-service

    KritikCVSS 9,3İstismar yokEPSS %1

    rocket.chat · rocket.chat6 Mar 2026

  • CVE-2026-48616
    37İzleyin

    Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.

    KritikCVSS 9,3İstismar yokEPSS %0

    rocket.chat · rocket.chat17 Haz 2026

  • CVE-2024-39713
    35İzleyin

    A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

    YüksekCVSS 8,6Kavram kanıtıEPSS %3

    rocket.chat · rocket.chat5 Ağu 2024

  • CVE-2022-35248
    35İzleyin

    A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasse

    YüksekCVSS 8,8İstismar yokEPSS %1

    rocket.chat · rocket.chat23 Eyl 2022

  • CVE-2022-32211
    35İzleyin

    A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password t

    YüksekCVSS 8,8İstismar yokEPSS %1

    rocket.chat · rocket.chat23 Eyl 2022

  • CVE-2023-23917
    35İzleyin

    A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.

    YüksekCVSS 8,8İstismar yokEPSS %1

    rocket.chat · rocket.chat23 Şub 2023

  • CVE-2026-30831
    32İzleyin

    Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer

    YüksekCVSS 8,0İstismar yokEPSS %1

    rocket.chat · rocket.chat6 Mar 2026

  • CVE-2021-22892
    31İzleyin

    An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be d

    YüksekCVSS 7,5İstismar yokEPSS %2

    rocket.chat · rocket.chat27 May 2021

  • CVE-2026-48929
    30İzleyin

    Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion

    YüksekCVSS 7,5İstismar yokEPSS %1

    rocket.chat · rocket.chat17 Haz 2026

  • CVE-2020-26763
    30İzleyin

    The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.

    YüksekCVSS 7,5İstismar yokEPSS %1

    rocket.chat · rocket.chat5 Tem 2021

  • CVE-2023-28356
    30İzleyin

    A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to ente

    YüksekCVSS 7,5İstismar yokEPSS %1

    rocket.chat · rocket.chat11 May 2023

  • CVE-2024-46935
    30İzleyin

    Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).

    YüksekCVSS 7,5İstismar yokEPSS %1

    rocket.chat · rocket.chat24 Eyl 2024

  • CVE-2026-65644
    30İzleyin

    Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/live

    YüksekCVSS 7,5İstismar yokEPSS %0

    rocket.chat · rocket.chat21 Ağu 2026

  • CVE-2025-7974
    30İzleyin

    rocket.chat Incorrect Authorization Information Disclosure Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    rocket.chat · rocket.chat2 Eyl 2025

  • CVE-2023-23911
    30İzleyin

    An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a use

    YüksekCVSS 7,5İstismar yokEPSS %0

    rocket.chat · rocket.chat10 Mar 2023

  • CVE-2022-30124
    27İzleyin

    An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a m

    OrtaCVSS 6,8İstismar yokEPSS %1

    rocket.chat · rocket.chat23 Eyl 2022

  • CVE-2026-30833
    27İzleyin

    Rocket.Chat: NoSQL injection in the EE ddp-streamer-service

    OrtaCVSS 6,9İstismar yokEPSS %0

    rocket.chat · rocket.chat6 Mar 2026