Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.71% | — | Matrix-react-sdk Project Matrix-react-sdk | 28/3/2023 | 17/6/2026 | matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial of service and potentially affecting… | |
| Modificada | Media (5.3) | 0.91% | — | Matrix React SDK | 28/3/2023 | 17/6/2026 | matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain… | |
| Modificada | Media (5.3) | 0.93% | — | Matrix Javascript SDK | 28/3/2023 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Variscite Matrix-gui | 8/3/2023 | 17/6/2026 | SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint. | |
| Modificada | Alta (7.8) | 0.22% | — | Citrix Workspace | 16/2/2023 | 17/6/2026 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | |
| Modificada | Media (5.5) | 0.26% | — | Citrix Workspace | 16/2/2023 | 17/6/2026 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. | |
| Modificada | Alta (7.8) | 0.27% | — | Citrix Virtual Apps AND Desktops | 16/2/2023 | 17/6/2026 | A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | |
| Modificada | Alta (7.5) | 1.0% | — | Citrix Application Delivery ControllerCitrix Gateway | 26/1/2023 | 17/6/2026 | Unauthenticated denial of service | |
| Modificada | Media (6.5) | 0.99% | — | Citrix GatewayCitrix Application Delivery Controller | 26/1/2023 | 17/6/2026 | Authenticated denial of service | |
| Modificada | Media (4.9) | 1.0% | 💥 PoC | Bitrix24 | 20/1/2023 | 17/6/2026 | Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php. | |
| Modificada | Alta (7.5) | 0.86% | 💥 PoC | Matrixssl | 18/1/2023 | 17/6/2026 | An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data. | |
| Modificada | Crítica (9.8) | 1.7% | — | Matrixssl | 9/1/2023 | 17/6/2026 | MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0. | |
| Modificada | Media (6.5) | 0.59% | — | Citrix Application Delivery Controller FirmwareCitrix Gateway | 26/12/2022 | 17/6/2026 | In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update. | |
| Analizada | Crítica (9.8) | 6.7% | ⚠ Explotación activa💥 PoC | Citrix Application Delivery Controller FirmwareCitrix Gateway Firmware | 13/12/2022 | 17/6/2026 | Unauthenticated remote arbitrary code execution | |
| Modificada | Media (5.3) | 0.91% | — | Matrix Synapse | 22/11/2022 | 17/6/2026 | Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived… | |
| Modificada | Media (6.8) | 0.54% | 💥 PoC | M5T Mediatrix 4102s Firmware | 17/11/2022 | 17/6/2026 | Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port. | |
| Modificada | Media (5.6) | 0.55% | — | Matrix IRC Bridge | 13/11/2022 | 17/6/2026 | A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version 0.36.0 is able to address this issue. The… | |
| Modificada | Crítica (9.8) | 0.64% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | User login brute force protection functionality bypass | |
| Modificada | Crítica (9.6) | 0.29% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | Remote desktop takeover via phishing | |
| Modificada | Crítica (9.8) | 1.1% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | Unauthorized access to Gateway user capabilities | |
| Modificada | Media (6.5) | 0.66% | — | Matrix-nio Project Matrix-nio | 29/9/2022 | 17/6/2026 | matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This… | |
| Modificada | Alta (7.5) | 0.62% | — | Matrix-rust-sdk | 29/9/2022 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software… | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Javascript SDK | 29/9/2022 | 17/6/2026 | Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’… | |
| Modificada | Alta (7.5) | 0.97% | — | Matrix Software Development KIT | 28/9/2022 | 17/6/2026 | Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in… | |
| Modificada | Alta (7.5) | 1.0% | — | Matrix Software Development KIT | 28/9/2022 | 17/6/2026 | Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker… |