Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.… | |
| Modificada | Media (5.3) | 1.4% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be… | |
| Modificada | Crítica (9.8) | 1.9% | — | Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+2 | 14/12/2021 | 17/6/2026 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to… | |
| Modificada | Media (5.9) | 0.66% | — | Matrix Javascript SDK | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in… | |
| Modificada | Alta (8.8) | 12% | — | Artworks Gallery IN Php, Css, Javascript, AND Mysql Project Artworks Gallery IN Php, Css, Javascript, AND Mysql | 17/11/2020 | 17/6/2026 | The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. | |
| Modificada | Alta (8.8) | 12% | — | Artworks Gallery IN Php, Css, Javascript, AND Mysql Project Artworks Gallery IN Php, Css, Javascript, AND Mysql | 17/11/2020 | 17/6/2026 | The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. | |
| Modificada | Media (6.1) | 1.4% | — | TC Custom Javascript Project TC Custom Javascript | 21/7/2020 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors. | |
| Modificada | Alta (8.1) | 3.0% | — | Verizon Serialize-javascript | 1/6/2020 | 17/6/2026 | serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". | |
| Modificada | Crítica (9.8) | 2.6% | — | Microsoft Research Javascript Cryptography Library | 15/4/2020 | 17/6/2026 | A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a server’s private ECC key (a key leakage attack) or… | |
| Modificada | Media (6.1) | 1.0% | — | Amazon AWS Javascript S3 Explorer | 13/2/2020 | 17/6/2026 | explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances. | |
| Modificada | Media (5.4) | 0.80% | — | Verizon Serialize-javascript | 5/12/2019 | 17/6/2026 | The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString()… | |
| Modificada | Crítica (9.8) | 7.5% | — | Microsoft Research Javascript Cryptography Library | 11/7/2018 | 17/6/2026 | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Chakra JavascriptMicrosoft JscriptMicrosoft Vbscript | 16/6/2016 | 17/6/2026 | The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption… | |
| Modificada | Media (5) | 4.8% | — | Javascript Xerver Http Server | 29/11/2009 | 16/6/2026 | CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 2.8% | — | Webkit Javascriptcore | 14/7/2008 | 16/6/2026 | JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger memory corruption, a different vulnerability… |