Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)1.2%—Matrix SynapseFedoraproject Fedora26/3/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on…
ModificadaMedia (6.5)1.0%—Jenkins Matrix Authorization Strategy18/3/202117/6/2026
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
ModificadaMedia (4.3)0.92%—Matrix-react-sdk Project Matrix-react-sdk2/3/202117/6/2026
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are…
ModificadaMedia (6.5)2.2%—Matrix SynapseFedoraproject Fedora26/2/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of…
ModificadaMedia (6.1)1.8%—Matrix SynapseFedoraproject Fedora26/2/202117/6/2026
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for…
ModificadaAlta (7.5)1.3%—Basic DSP Matrix Project Basic DSP Matrix26/1/202117/6/2026
An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed.
ModificadaMedia (4.3)2.0%—Citrix Secure Mail6/1/202117/6/2026
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the…
ModificadaMedia (6.5)2.1%—Citrix Secure Mail6/1/202117/6/2026
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary…
ModificadaAlta (7.5)1.8%—Matrixssl30/12/202017/6/2026
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431.
ModificadaAlta (8.8)2.7%—Citrix Virtual Apps AND DesktopsCitrix XenappCitrix Xendesktop14/12/202017/6/2026
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.
ModificadaAlta (7.5)1.3%—Citrix Gateway Plug-in14/12/202017/6/2026
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.
ModificadaCrítica (9.8)1.7%—Citrix Gateway Plug-in14/12/202017/6/2026
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks
ModificadaMedia (6.5)2.4%—Matrix SynapseFedoraproject Fedora9/12/202017/6/2026
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or…
ModificadaMedia (6.5)1.1%—Bitrix24 Bitrix Framework2/12/202017/6/2026
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on…
ModificadaAlta (7.5)3.0%—Matrix SynapseFedoraproject Fedora24/11/202017/6/2026
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the…
ModificadaCrítica (9.8)1.8%—Aviatrix Controller17/11/202017/6/2026
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.
ModificadaAlta (7.5)1.2%—Aviatrix Controller17/11/202017/6/2026
An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.
ModificadaAlta (7.5)0.92%—Aviatrix Controller17/11/202017/6/2026
An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
ModificadaAlta (7.5)1.5%—Aviatrix Controller17/11/202017/6/2026
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
ModificadaAlta (7.5)1.5%—Aviatrix Controller17/11/202017/6/2026
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
ModificadaAlta (8.8)1.5%—Aviatrix Controller17/11/202017/6/2026
An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.
ModificadaAlta (8.8)2.4%—Citrix Sd-wan16/11/202017/6/2026
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
ModificadaAlta (7.5)1.5%—Citrix Sd-wan16/11/202017/6/2026
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
ModificadaCrítica (9.8)11%—Citrix Sd-wan16/11/202017/6/2026
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
ModificadaAlta (8.8)3.5%—Citrix Virtual Apps AND Desktops16/11/202017/6/2026
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
Orbitaley — Vulnerabilidades