Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.75% | — | Matrix Synapse | 6/6/2023 | 17/6/2026 | Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are true: 1. JSON Web Tokens are enabled for login via the `jwt_config.enabled`… | |
| Modificada | Media (4.3) | 0.98% | — | Matrix Synapse | 26/5/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to an arbitrary homeserver Y. Synapse instances with federation disabled are not affected. In… | |
| Modificada | Media (6.5) | 0.94% | — | Matrix Synapse | 26/5/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be… | |
| Modificada | Media (5) | 0.64% | — | Matrix Synapse | 26/5/2023 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that a homeserver receiving some events can validate that those events are legitimate and permitted in… | |
| Modificada | Media (6.8) | 0.63% | — | Razer Synapse | 27/1/2023 | 17/6/2026 | Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write… | |
| Modificada | Media (5.3) | 0.91% | — | Matrix Synapse | 22/11/2022 | 17/6/2026 | Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived… | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Synapse | 2/9/2022 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In… | |
| Modificada | Media (6.5) | 1.7% | — | Matrix SynapseFedoraproject Fedora | 28/6/2022 | 17/6/2026 | Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem,… | |
| Modificada | Alta (7.3) | 0.90% | — | Razer Synapse | 23/3/2022 | 17/6/2026 | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there. | |
| Modificada | Alta (7.5) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 23/11/2021 | 17/6/2026 | Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the affected endpoint. The last 2 directories… | |
| Modificada | Baja (3.1) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 31/8/2021 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms with `shared` history visibility.… | |
| Modificada | Baja (3.1) | 0.90% | — | Matrix SynapseFedoraproject Fedora | 31/8/2021 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where the vulnerable homeserver is in the room… | |
| Modificada | Media (5.3) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 11/5/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against… | |
| Modificada | Media (5.5) | 0.50% | — | Razer Synapse | 14/4/2021 | 17/6/2026 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker… | |
| Modificada | Media (5.5) | 0.52% | — | Razer Synapse | 14/4/2021 | 17/6/2026 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker can… | |
| Modificada | Media (6.5) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause… | |
| Modificada | Media (6.3) | 0.94% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used.… | |
| Modificada | Media (6.5) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 12/4/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause… | |
| Modificada | Media (6.1) | 1.4% | — | Matrix SynapseFedoraproject Fedora | 26/3/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection.… | |
| Modificada | Alta (8.2) | 1.2% | — | Matrix SynapseFedoraproject Fedora | 26/3/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on… | |
| Modificada | Media (6.5) | 2.2% | — | Matrix SynapseFedoraproject Fedora | 26/2/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of… | |
| Modificada | Media (6.1) | 1.8% | — | Matrix SynapseFedoraproject Fedora | 26/2/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for… | |
| Modificada | Media (6.5) | 2.4% | — | Matrix SynapseFedoraproject Fedora | 9/12/2020 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or… | |
| Modificada | Alta (7.5) | 3.0% | — | Matrix SynapseFedoraproject Fedora | 24/11/2020 | 17/6/2026 | Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the… | |
| Modificada | Media (6.1) | 1.9% | — | Matrix Synapse | 19/10/2020 | 17/6/2026 | AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/*/fallback/web or… |