Current Conditions
São Paulo
céu limpo

26 ℃
69%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 17:30:01
  1. [USD] USD 65,795.37
  1. [BRL] BRL 345,787.58 [USD] USD 65,795.37 [GBP] GBP 49,576.62 [EUR] EUR 57,140.98
    Price index provided by blockchain.info.
  2. Bitcoin Core version 28.4 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-12559] [Modified: 03-12-2025] [Analyzed] [V3.1 S4.3:MEDIUM] Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

[CVE-2025-12421] [Modified: 03-12-2025] [Analyzed] [V3.1 S9.9:CRITICAL] Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

[CVE-2025-66359] [Modified: 03-12-2025] [Analyzed] [V3.1 S8.5:HIGH] An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerability.

[CVE-2025-66360] [Modified: 03-12-2025] [Analyzed] [V3.1 S8.8:HIGH] An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.

[CVE-2025-66361] [Modified: 03-12-2025] [Analyzed] [V3.1 S6.5:MEDIUM] An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

[CVE-2025-58294] [Modified: 02-12-2025] [Analyzed] [V3.1 S6.2:MEDIUM] Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

[CVE-2025-58303] [Modified: 02-12-2025] [Analyzed] [V3.1 S8.4:HIGH] UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-58307] [Modified: 02-12-2025] [Analyzed] [V3.1 S6.4:MEDIUM] UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-58309] [Modified: 02-12-2025] [Analyzed] [V3.1 S6.8:MEDIUM] Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

[CVE-2025-58310] [Modified: 02-12-2025] [Analyzed] [V3.1 S8.0:HIGH] Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

[CVE-2025-58312] [Modified: 02-12-2025] [Analyzed] [V3.1 S5.1:MEDIUM] Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-58314] [Modified: 02-12-2025] [Analyzed] [V3.1 S6.6:MEDIUM] Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

[CVE-2025-58315] [Modified: 02-12-2025] [Analyzed] [V3.1 S5.5:MEDIUM] Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

[CVE-2025-58316] [Modified: 02-12-2025] [Analyzed] [V3.1 S7.3:HIGH] DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-64311] [Modified: 02-12-2025] [Analyzed] [V3.1 S5.1:MEDIUM] Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

[CVE-2025-64313] [Modified: 02-12-2025] [Analyzed] [V3.1 S5.3:MEDIUM] Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

[CVE-2025-64314] [Modified: 02-12-2025] [Analyzed] [V3.1 S9.3:CRITICAL] Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.

[CVE-2025-64315] [Modified: 02-12-2025] [Analyzed] [V3.1 S4.4:MEDIUM] Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.

[CVE-2025-58302] [Modified: 02-12-2025] [Analyzed] [V3.1 S8.4:HIGH] Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

[CVE-2025-58304] [Modified: 02-12-2025] [Analyzed] [V3.1 S4.9:MEDIUM] Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.