Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

69 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.86%—Matrix Synapse8/11/201917/6/2026
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
ModificadaAlta (7.5)1.8%—Matrix SydentMatrix Synapse9/5/201917/6/2026
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
ModificadaAlta (7.5)2.4%—Matrix SynapseFedoraproject Fedora21/3/201917/6/2026
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
ModificadaAlta (8.8)0.58%—Tibco Datasynapse Gridserver Manager13/11/201817/6/2026
The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery (CSRF). Affected releases are TIBCO Software Inc. TIBCO DataSynapse GridServer Manager: versions…
ModificadaAlta (8.8)1.5%—Matrix SynapseDebian Linux18/9/201817/6/2026
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
ModificadaAlta (7.5)1.8%—Matrix Synapse14/6/201817/6/2026
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
ModificadaAlta (7.5)1.8%—Matrix Synapse13/6/201817/6/2026
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.
ModificadaAlta (7.5)1.5%—Matrix Synapse2/5/201817/6/2026
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
ModificadaMedia (5.4)0.68%—Tibco Datasynapse Gridserver Manager1/5/201817/6/2026
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack.…
ModificadaMedia (6.8)0.18%—Tibco Datasynapse Gridserver Manager1/5/201817/6/2026
The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ciphers. A malicious actor could theoretically compromise the traffic between any…
ModificadaCrítica (9.8)18%💥 PoCApache SynapseOracle Financial Services Market Risk Measurement AND ManagementOracle Peoplesoft Enterprise Peopletools11/12/201717/6/2026
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence…
ModificadaAlta (7.8)0.29%—Razer Synapse13/9/201717/6/2026
rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle to \Device\PhysicalMemory, IOCTL 0x22A064, and ZwMapViewOfSection.
ModificadaAlta (7.8)0.36%—Razer Synapse18/8/201717/6/2026
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or (2) RazerConfigNativeLOC.dll file.
ModificadaAlta (8.4)0.41%—Razer Synapse18/8/201717/6/2026
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.
ModificadaMedia (5.5)0.33%—Razerzone Razer Synapse2/8/201717/6/2026
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse that can cause an out of bounds read operation to occur due to a field within the IOCTL data being used as a length.
ModificadaCrítica (9.8)86%💥 ExploitRazer Synapse2/8/201717/6/2026
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
ModificadaMedia (5.4)0.27%—Synapse Ishuttle21/10/201417/6/2026
The iShuttle (aka com.synapse.ishuttle_user) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (10)1.4%—Mobisynapse Moffice-outlook Sync7/3/201216/6/2026
Unspecified vulnerability in the mOffice - Outlook sync (com.innov8tion.isharesync) application 3.1 for Android has unknown impact and attack vectors.
ModificadaMedia (5)2.4%—Rene Tegel Visual Synapse8/10/201016/6/2026
Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.