Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Humanica Humatrix | 10/9/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | |
| Modificada | Crítica (9.8) | 2.4% | — | Humanica Humatrix 7 | 18/8/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the… | |
| Modificada | Media (5.3) | 1.3% | — | Humanica Humatrix 7 | 18/8/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI. | |
| Modificada | Alta (7.5) | 2.1% | — | Humanica Humatrix 7 | 12/8/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to personalData/resumeDetail.cfm. This includes personal information and other sensitive data. | |
| Modificada | Crítica (9.8) | 3.6% | — | Matrixssl | 29/7/2019 | 17/6/2026 | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value… | |
| Modificada | Crítica (9.8) | 1.6% | — | Matrixssl | 9/7/2019 | 17/6/2026 | MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling. | |
| Modificada | Alta (7.5) | 1.8% | — | Matrix SydentMatrix Synapse | 9/5/2019 | 17/6/2026 | An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID. | |
| Modificada | Media (6.1) | 1.1% | — | Tibco Activematrix BPMTibco Silver Fabric Enabler | 24/4/2019 | 17/6/2026 | The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a vulnerability wherein a malicious URL could trick a user into visiting a… | |
| Modificada | Media (4.6) | 0.78% | — | Tibco Activematrix Business Process ManagementTibco Silver Fabric Enabler | 24/4/2019 | 17/6/2026 | The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contains vulnerabilities where an authenticated user can change settings that can theoretically adversely impact other users. Affected… | |
| Modificada | Crítica (9.8) | 2.5% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver… | |
| Modificada | Alta (8.8) | 2.1% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric,… | |
| Modificada | Alta (8.8) | 0.95% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric… | |
| Modificada | Media (6.1) | 0.69% | — | Tibco Activematrix Business Process ManagementTibco Silver Fabric Enabler | 24/4/2019 | 17/6/2026 | The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain cross site scripting (XSS) and cross-site request forgery… | |
| Modificada | Media (5.9) | 1.9% | — | Matrix Sydent | 19/4/2019 | 17/6/2026 | util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns… | |
| Modificada | Alta (8.1) | 2.9% | — | Tibco Activematrix Businessworks | 9/4/2019 | 17/6/2026 | The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required. This possibility is restricted to circumstances where HTTP "Basic… | |
| Modificada | Crítica (9.8) | 1.4% | — | Matrixssl | 8/4/2019 | 17/6/2026 | pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certificate verification because of missing validation in psRsaDecryptPubExt in crypto/pubkey/rsa_pub.c. | |
| Modificada | Alta (7.5) | 2.4% | — | Matrix SynapseFedoraproject Fedora | 21/3/2019 | 17/6/2026 | Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Matrix Storage Manager | 14/3/2019 | 17/6/2026 | Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.9) | 3.5% | — | Jenkins Matrix ProjectRedhat Openshift Container Platform | 8/3/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM. | |
| Modificada | Alta (8.8) | 1.5% | — | Matrix SynapseDebian Linux | 18/9/2018 | 17/6/2026 | Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation. | |
| Modificada | Alta (7.5) | 2.4% | — | Tibco Activematrix BusinessworksActivematrix Businessworks Distribution FOR Tibco Silver Fabric | 8/8/2018 | 17/6/2026 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages,… | |
| Modificada | Media (4.7) | 0.27% | — | Matrixssl | 15/6/2018 | 17/6/2026 | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. | |
| Modificada | Alta (7.5) | 1.8% | — | Matrix Synapse | 14/6/2018 | 17/6/2026 | In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force. | |
| Modificada | Alta (7.5) | 1.8% | — | Matrix Synapse | 13/6/2018 | 17/6/2026 | The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly. | |
| Modificada | Alta (7.5) | 1.5% | — | Matrix Synapse | 2/5/2018 | 17/6/2026 | Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018. |