Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Matrix Javascript SDK28/9/202217/6/2026
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker…
ModificadaAlta (7.5)1.3%—Matrix Javascript SDK28/9/202217/6/2026
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.…
ModificadaAlta (7.5)0.97%—Matrix Software Development KIT28/9/202217/6/2026
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a…
ModificadaMedia (5.3)0.85%—Matrix Software Development KIT28/9/202217/6/2026
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible…
ModificadaMedia (5.3)1.3%—Matrix Javascript SDK28/9/202217/6/2026
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be…
ModificadaAlta (8.8)0.86%—Matrix IRC Bridge13/9/202217/6/2026
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the channel. The vulnerability has been patched…
ModificadaMedia (6.3)0.88%—Matrix IRC Bridge13/9/202217/6/2026
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc perform parsing of such modes incorrectly,…
ModificadaMedia (5.3)0.36%—Matrix Dendrite12/9/202217/6/2026
Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note…
ModificadaMedia (5.3)0.57%—Squiz Matrix6/9/202217/6/2026
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about…
ModificadaAlta (7.5)1.2%—Matrix Synapse2/9/202217/6/2026
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In…
ModificadaAlta (8.8)0.82%—Matrix DendriteGomatrixserverlib19/8/202217/6/2026
gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to…
ModificadaAlta (8.8)0.77%—Aviatrix Gateway15/8/202217/6/2026
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
ModificadaMedia (6.1)0.52%—Citrix GatewayCitrix Application Delivery Controller Firmware28/7/202217/6/2026
Unauthenticated redirection to a malicious website
ModificadaMedia (6.5)0.52%—Jenkins Matrix Reloaded30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.
ModificadaMedia (5.4)0.60%—Jenkins Matrix Reloaded30/6/202217/6/2026
Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
ModificadaMedia (5.4)0.54%—Bitrix24 Bitrix Site Manager30/6/202217/6/2026
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site…
ModificadaMedia (6.5)1.7%—Matrix SynapseFedoraproject Fedora28/6/202217/6/2026
Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem,…
ModificadaMedia (5.3)0.98%—Citrix Application Delivery Management16/6/202217/6/2026
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
ModificadaAlta (8.1)12%—Citrix Application Delivery Management16/6/202217/6/2026
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.
ModificadaAlta (7.1)0.18%—Citrix Gateway Plug-in26/5/202217/6/2026
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
ModificadaAlta (8.8)1.0%—Matrix IRC Bridge5/5/202217/6/2026
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2. Refrain from replying to messages…
ModificadaAlta (8.8)2.8%—Citrix Xenmobile Server19/4/202217/6/2026
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
ModificadaBaja (2.7)0.66%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+1013/4/202217/6/2026
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
ModificadaMedia (6.1)0.53%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+813/4/202217/6/2026
Reflected cross site scripting (XSS)
ModificadaMedia (6.1)0.48%—Citrix Storefront Server13/4/202217/6/2026
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
Orbitaley — Vulnerabilidades