Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Trixie TX9 Automatic Food Dispenser Firmware | 26/7/2021 | 17/6/2026 | TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g.,… | |
| Modificada | Alta (7.5) | 1.3% | — | Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux | 18/7/2021 | 17/6/2026 | uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality). | |
| Modificada | Media (4.9) | 0.94% | — | Matrix-appservice-bridge | 16/6/2021 | 17/6/2026 | Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it… | |
| Modificada | Crítica (9.8) | 4.3% | — | Matrix OLM | 16/6/2021 | 17/6/2026 | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations. | |
| Modificada | Alta (7.5) | 1.0% | — | Citrix Cloud Connector | 16/6/2021 | 17/6/2026 | Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of… | |
| Modificada | Media (6.5) | 3.0% | 💥 PoC | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller Firmware | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a… | |
| Modificada | Media (6.5) | 0.42% | — | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from… | |
| Modificada | Alta (7.8) | 0.24% | — | Citrix Workspace | 27/5/2021 | 17/6/2026 | An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. | |
| Modificada | Crítica (9.8) | 1.1% | — | Citrix Sharefile Storagezones Controller | 27/5/2021 | 17/6/2026 | A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller. | |
| Modificada | Alta (7.8) | 0.37% | — | Matrix-react-sdk Project Matrix-react-sdk | 17/5/2021 | 17/6/2026 | Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab.… | |
| Modificada | Media (5.3) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 11/5/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against… | |
| Modificada | Alta (7.8) | 0.31% | — | Aviatrix VPN Client | 29/4/2021 | 17/6/2026 | Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators. | |
| Modificada | Alta (8.8) | 2.1% | — | Acemetrix Jquery-deparam | 23/4/2021 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype. | |
| Modificada | Alta (7.5) | 0.90% | — | Aviatrix Openvpn | 21/4/2021 | 17/6/2026 | Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system. | |
| Modificada | Alta (7.5) | 1.6% | — | Aviatrix Controller | 21/4/2021 | 17/6/2026 | Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security. | |
| Modificada | Media (6.5) | 1.0% | — | Matrix-media-repo Project Matrix-media-repo | 19/4/2021 | 17/6/2026 | matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user could upload a relatively small image in terms of file size, using… | |
| Modificada | Media (5.7) | 0.93% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d. | |
| Modificada | Media (6.5) | 1.2% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port… | |
| Modificada | Alta (7.5) | 1.8% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response size for requests it makes to remote Matrix… | |
| Modificada | Media (4.3) | 0.93% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No… | |
| Modificada | Media (6.5) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause… | |
| Modificada | Media (6.3) | 0.94% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used.… | |
| Modificada | Media (6.5) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause… | |
| Modificada | Crítica (9.8) | 2.1% | — | Latrix Project Latrix | 2/4/2021 | 17/6/2026 | An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution. | |
| Modificada | Media (6.1) | 1.4% | — | Matrix SynapseFedoraproject Fedora | 26/3/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection.… |