Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker… | |
| Modificada | Alta (7.5) | 1.3% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.… | |
| Modificada | Alta (7.5) | 0.97% | — | Matrix Software Development KIT | 28/9/2022 | 17/6/2026 | matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a… | |
| Modificada | Media (5.3) | 0.85% | — | Matrix Software Development KIT | 28/9/2022 | 17/6/2026 | matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible… | |
| Modificada | Media (5.3) | 1.3% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be… | |
| Modificada | Alta (8.8) | 0.86% | — | Matrix IRC Bridge | 13/9/2022 | 17/6/2026 | matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the channel. The vulnerability has been patched… | |
| Modificada | Media (6.3) | 0.88% | — | Matrix IRC Bridge | 13/9/2022 | 17/6/2026 | matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc perform parsing of such modes incorrectly,… | |
| Modificada | Media (5.3) | 0.36% | — | Matrix Dendrite | 12/9/2022 | 17/6/2026 | Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note… | |
| Modificada | Media (5.3) | 0.57% | — | Squiz Matrix | 6/9/2022 | 17/6/2026 | Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about… | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Synapse | 2/9/2022 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In… | |
| Modificada | Alta (8.8) | 0.82% | — | Matrix DendriteGomatrixserverlib | 19/8/2022 | 17/6/2026 | gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to… | |
| Modificada | Alta (8.8) | 0.77% | — | Aviatrix Gateway | 15/8/2022 | 17/6/2026 | An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands. | |
| Modificada | Media (6.1) | 0.52% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 28/7/2022 | 17/6/2026 | Unauthenticated redirection to a malicious website | |
| Modificada | Media (6.5) | 0.52% | — | Jenkins Matrix Reloaded | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Matrix Reloaded | 30/6/2022 | 17/6/2026 | Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | |
| Modificada | Media (5.4) | 0.54% | — | Bitrix24 Bitrix Site Manager | 30/6/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site… | |
| Modificada | Media (6.5) | 1.7% | — | Matrix SynapseFedoraproject Fedora | 28/6/2022 | 17/6/2026 | Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem,… | |
| Modificada | Media (5.3) | 0.98% | — | Citrix Application Delivery Management | 16/6/2022 | 17/6/2026 | Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | |
| Modificada | Alta (8.1) | 12% | — | Citrix Application Delivery Management | 16/6/2022 | 17/6/2026 | Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted. | |
| Modificada | Alta (7.1) | 0.18% | — | Citrix Gateway Plug-in | 26/5/2022 | 17/6/2026 | An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM. | |
| Modificada | Alta (8.8) | 1.0% | — | Matrix IRC Bridge | 5/5/2022 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2. Refrain from replying to messages… | |
| Modificada | Alta (8.8) | 2.8% | — | Citrix Xenmobile Server | 19/4/2022 | 17/6/2026 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution. | |
| Modificada | Baja (2.7) | 0.66% | — | Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+10 | 13/4/2022 | 17/6/2026 | Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | |
| Modificada | Media (6.1) | 0.53% | — | Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+8 | 13/4/2022 | 17/6/2026 | Reflected cross site scripting (XSS) | |
| Modificada | Media (6.1) | 0.48% | — | Citrix Storefront Server | 13/4/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 |