Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 24% | 💥 PoC | Bitrix24 | 1/11/2023 | 17/6/2026 | Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url". | |
| Modificada | Crítica (9.6) | 1.1% | — | Bitrix24 | 1/11/2023 | 17/6/2026 | Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via polluting… | |
| Modificada | Crítica (9.6) | 0.71% | — | Bitrix24 | 1/11/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege. | |
| Modificada | Media (5.4) | 0.59% | — | Bitrix24 | 1/11/2023 | 17/6/2026 | A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload. | |
| Modificada | Alta (8.8) | 1.4% | — | Bitrix24 | 1/11/2023 | 17/6/2026 | Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization. | |
| Modificada | Alta (8.8) | 1.2% | — | Bitrix24 | 1/11/2023 | 17/6/2026 | Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file. | |
| Modificada | Media (5.3) | 0.90% | — | Matrix SynapseFedoraproject Fedora | 31/10/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a… | |
| Modificada | Alta (7.5) | 0.89% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/10/2023 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server | |
| Modificada | Media (4.9) | 1.2% | — | Matrix SynapseFedoraproject Fedora | 10/10/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/10/2023 | 31/7/2026 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | |
| Modificada | Alta (8.8) | 0.25% | — | Gtmetrix | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.7 versions. | |
| Modificada | Crítica (9) | 0.32% | — | Matrix Hookshot | 27/9/2023 | 17/6/2026 | matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `generic.allowJsTransformationFunctions` in their config), may be vulnerable to an attack where it is possible to break out of the `vm2` sandbox… | |
| Modificada | Media (4.3) | 0.78% | — | Matrix SynapseFedoraproject Fedora | 27/9/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show… | |
| Modificada | Baja (3.7) | 0.39% | — | Matrix SynapseFedoraproject Fedora | 27/9/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the… | |
| Modificada | Alta (7.2) | 1.2% | — | Bosch RTS Vlink Virtual Matrix | 18/9/2023 | 17/6/2026 | A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface. | |
| Modificada | Media (5.4) | 0.52% | — | Turt2live Matrix-media-repo | 8/9/2023 | 17/6/2026 | matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inline` upon download. This vulnerability could be leveraged to… | |
| Modificada | Media (6.1) | 0.38% | — | Gtmetrix | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.6 versions. | |
| Modificada | Baja (3.7) | 0.60% | — | Matrix IRC Bridge | 4/8/2023 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the… | |
| Modificada | Media (6.5) | 0.47% | — | Matrix-appservice-bridge | 4/8/2023 | 17/6/2026 | matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impersonate users when using the provisioning API. The library does not check that the… | |
| Modificada | Crítica (9.8) | 0.86% | — | Matrix IRC Bridge | 4/8/2023 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are… | |
| Modificada | Media (5.3) | 0.27% | — | Matrix Sydent | 4/8/2023 | 17/6/2026 | Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack. Attackers with privileged access to the… | |
| Modificada | Alta (8) | 1.3% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Privilege Escalation to root administrator (nsroot) | |
| Modificada | Media (6.1) | 2.6% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 5/8/2026 | Unauthenticated remote code execution | |
| Modificada | Alta (7.5) | 0.60% | — | Intergard Smartgard Silver With Matrix Keyboard | 19/7/2023 | 17/6/2026 | A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Query Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high.… |