Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.71%—Matrix-react-sdk Project Matrix-react-sdk28/3/202317/6/2026
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial of service and potentially affecting…
ModificadaMedia (5.3)0.91%—Matrix React SDK28/3/202317/6/2026
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain…
ModificadaMedia (5.3)0.93%—Matrix Javascript SDK28/3/202317/6/2026
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the…
ModificadaCrítica (9.8)1.2%—Variscite Matrix-gui8/3/202317/6/2026
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.
ModificadaAlta (7.8)0.22%—Citrix Workspace16/2/202317/6/2026
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
ModificadaMedia (5.5)0.26%—Citrix Workspace16/2/202317/6/2026
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
ModificadaAlta (7.8)0.27%—Citrix Virtual Apps AND Desktops16/2/202317/6/2026
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
ModificadaAlta (7.5)1.0%—Citrix Application Delivery ControllerCitrix Gateway26/1/202317/6/2026
Unauthenticated denial of service
ModificadaMedia (6.5)0.99%—Citrix GatewayCitrix Application Delivery Controller26/1/202317/6/2026
Authenticated denial of service
ModificadaMedia (4.9)1.0%💥 PoCBitrix2420/1/202317/6/2026
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.
ModificadaAlta (7.5)0.86%💥 PoCMatrixssl18/1/202317/6/2026
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
ModificadaCrítica (9.8)1.7%—Matrixssl9/1/202317/6/2026
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.
ModificadaMedia (6.5)0.59%—Citrix Application Delivery Controller FirmwareCitrix Gateway26/12/202217/6/2026
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
AnalizadaCrítica (9.8)6.7%⚠ Explotación activa💥 PoCCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
ModificadaMedia (5.3)0.91%—Matrix Synapse22/11/202217/6/2026
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived…
ModificadaMedia (6.8)0.54%💥 PoCM5T Mediatrix 4102s Firmware17/11/202217/6/2026
Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.
ModificadaMedia (5.6)0.55%—Matrix IRC Bridge13/11/202217/6/2026
A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version 0.36.0 is able to address this issue. The…
ModificadaCrítica (9.8)0.64%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
User login brute force protection functionality bypass
ModificadaCrítica (9.6)0.29%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Remote desktop takeover via phishing
ModificadaCrítica (9.8)1.1%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Unauthorized access to Gateway user capabilities
ModificadaMedia (6.5)0.66%—Matrix-nio Project Matrix-nio29/9/202217/6/2026
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This…
ModificadaAlta (7.5)0.62%—Matrix-rust-sdk29/9/202217/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software…
ModificadaAlta (7.5)1.2%—Matrix Javascript SDK29/9/202217/6/2026
Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’…
ModificadaAlta (7.5)0.97%—Matrix Software Development KIT28/9/202217/6/2026
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in…
ModificadaAlta (7.5)1.0%—Matrix Software Development KIT28/9/202217/6/2026
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker…
Orbitaley — Vulnerabilidades