Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.4%—Trixie TX9 Automatic Food Dispenser Firmware26/7/202117/6/2026
TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g.,…
ModificadaAlta (7.5)1.3%—Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux18/7/202117/6/2026
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
ModificadaMedia (4.9)0.94%—Matrix-appservice-bridge16/6/202117/6/2026
Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it…
ModificadaCrítica (9.8)4.3%—Matrix OLM16/6/202117/6/2026
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
ModificadaAlta (7.5)1.0%—Citrix Cloud Connector16/6/202117/6/2026
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of…
ModificadaMedia (6.5)3.0%💥 PoCCitrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller Firmware16/6/202117/6/2026
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a…
ModificadaMedia (6.5)0.42%—Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop16/6/202117/6/2026
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from…
ModificadaAlta (7.8)0.24%—Citrix Workspace27/5/202117/6/2026
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.
ModificadaCrítica (9.8)1.1%—Citrix Sharefile Storagezones Controller27/5/202117/6/2026
A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.
ModificadaAlta (7.8)0.37%—Matrix-react-sdk Project Matrix-react-sdk17/5/202117/6/2026
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab.…
ModificadaMedia (5.3)1.6%—Matrix SynapseFedoraproject Fedora11/5/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against…
ModificadaAlta (7.8)0.31%—Aviatrix VPN Client29/4/202117/6/2026
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
ModificadaAlta (8.8)2.1%—Acemetrix Jquery-deparam23/4/202117/6/2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
ModificadaAlta (7.5)0.90%—Aviatrix Openvpn21/4/202117/6/2026
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
ModificadaAlta (7.5)1.6%—Aviatrix Controller21/4/202117/6/2026
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.
ModificadaMedia (6.5)1.0%—Matrix-media-repo Project Matrix-media-repo19/4/202117/6/2026
matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user could upload a relatively small image in terms of file size, using…
ModificadaMedia (5.7)0.93%—Matrix Sydent15/4/202117/6/2026
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
ModificadaMedia (6.5)1.2%—Matrix Sydent15/4/202117/6/2026
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port…
ModificadaAlta (7.5)1.8%—Matrix Sydent15/4/202117/6/2026
Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response size for requests it makes to remote Matrix…
ModificadaMedia (4.3)0.93%—Matrix Sydent15/4/202117/6/2026
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No…
ModificadaMedia (6.5)1.6%—Matrix SynapseFedoraproject Fedora12/4/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause…
ModificadaMedia (6.3)0.94%—Matrix SynapseFedoraproject Fedora12/4/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used.…
ModificadaMedia (6.5)1.5%—Matrix SynapseFedoraproject Fedora12/4/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause…
ModificadaCrítica (9.8)2.1%—Latrix Project Latrix2/4/202117/6/2026
An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution.
ModificadaMedia (6.1)1.4%—Matrix SynapseFedoraproject Fedora26/3/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection.…
Orbitaley — Vulnerabilidades