Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response size for requests it makes to remote Matrix… | |
| Modificada | Media (4.3) | 0.93% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No… | |
| Modificada | Media (6.5) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause… | |
| Modificada | Media (6.3) | 0.94% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used.… | |
| Modificada | Media (6.5) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause… | |
| Modificada | Media (6.1) | 1.4% | — | Matrix SynapseFedoraproject Fedora | 26/3/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection.… | |
| Modificada | Alta (8.2) | 1.2% | — | Matrix SynapseFedoraproject Fedora | 26/3/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on… | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Matrix Authorization Strategy | 18/3/2021 | 17/6/2026 | An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders. | |
| Modificada | Media (4.3) | 0.92% | — | Matrix-react-sdk Project Matrix-react-sdk | 2/3/2021 | 17/6/2026 | matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are… | |
| Modificada | Media (6.5) | 2.2% | — | Matrix SynapseFedoraproject Fedora | 26/2/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of… | |
| Modificada | Media (6.1) | 1.8% | — | Matrix SynapseFedoraproject Fedora | 26/2/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for… | |
| Modificada | Alta (7.5) | 1.3% | — | Basic DSP Matrix Project Basic DSP Matrix | 26/1/2021 | 17/6/2026 | An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed. | |
| Modificada | Alta (7.5) | 1.8% | — | Matrixssl | 30/12/2020 | 17/6/2026 | In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431. | |
| Modificada | Media (6.5) | 2.4% | — | Matrix SynapseFedoraproject Fedora | 9/12/2020 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or… | |
| Modificada | Alta (7.5) | 3.0% | — | Matrix SynapseFedoraproject Fedora | 24/11/2020 | 17/6/2026 | Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the… | |
| Modificada | Media (6.1) | 1.9% | — | Matrix Synapse | 19/10/2020 | 17/6/2026 | AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/*/fallback/web or… | |
| Modificada | Media (5.4) | 0.92% | — | Jenkins Matrix Authorization Strategy | 15/7/2020 | 17/6/2026 | Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 1.0% | — | Jenkins Matrix Project | 15/7/2020 | 17/6/2026 | Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 0.92% | — | Jenkins Matrix Project | 15/7/2020 | 17/6/2026 | Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 0.55% | — | Matrix42 Workspace Management | 15/4/2020 | 17/6/2026 | The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues. | |
| Modificada | Media (5.4) | 0.77% | — | Matrix42 Workspace Management | 15/4/2020 | 17/6/2026 | Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software. | |
| Modificada | Crítica (9.1) | 3.4% | — | Squiz Matrix | 11/12/2019 | 17/6/2026 | An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during… | |
| Modificada | Alta (7.5) | 4.8% | — | Squiz Matrix | 11/12/2019 | 17/6/2026 | An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during… | |
| Modificada | Crítica (9.8) | 0.86% | — | Matrix Synapse | 8/11/2019 | 17/6/2026 | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers. | |
| Modificada | Media (5.9) | 1.2% | — | Matrixssl | 3/10/2019 | 17/6/2026 | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because crypto/pubkey/ecc_math.c scalar multiplication leaks… |