Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.18% | — | Simopro Technology Winmatrix AgentAI | 16/4/2026 | 17/6/2026 | WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed. | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | Tibco Activematrix BusinessworksAITibco Enterprise AdministratorAI | 24/3/2026 | 17/6/2026 | Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour. | |
| Pendiente de análisis | Alta (7.7) | 0.29% | — | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 23/3/2026 | 17/6/2026 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup | |
| Analizada | Crítica (9.3) | 4.0% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 23/3/2026 | 17/6/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Element Server Suite Community EditionAIMatrix-toolsAIElement ESS Community Helm ChartAI | 12/2/2026 | 17/6/2026 | Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network… | |
| Analizada | Alta (7.7) | 4.7% | — | Inextrix Astpp | 11/2/2026 | 17/6/2026 | ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions… | |
| Analizada | Alta (8.7) | 0.60% | — | Inextrix Astpp | 11/2/2026 | 17/6/2026 | ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the… | |
| Aplazada | Media (5.8) | 0.33% | — | Langsmith Python SDKAIMatrix Javascript SDKAI | 9/2/2026 | 17/6/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive… | |
| Aplazada | Media (6.8) | 0.16% | — | Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+1 | 22/1/2026 | 17/6/2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers… | |
| Aplazada | Alta (8.5) | 0.16% | — | Vb-audio MatrixAIVb-audio Matrix CoconutAI | 22/1/2026 | 17/6/2026 | VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local privilege escalation vulnerability in the VBMatrix VAIO virtual audio driver (vbmatrixvaio64*_win10.sys). The driver allocates a 128-byte non-paged pool buffer and, upon receiving IOCTL 0x222060, maps… | |
| Aplazada | Media (6.9) | 0.21% | — | Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+1 | 22/1/2026 | 17/6/2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers… | |
| Aplazada | Media (6.9) | 0.18% | — | Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+1 | 22/1/2026 | 17/6/2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers… | |
| Aplazada | Alta (7.1) | 0.18% | — | Matrixaddons Easy InvoiceAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy Invoice easy-invoice allows DOM-Based XSS.This issue affects Easy Invoice: from n/a through <= 2.0.9. | |
| Analizada | Baja (1.3) | 0.41% | — | Matrix-rust-sdk | 9/12/2025 | 17/6/2026 | matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join… | |
| Aplazada | Media (6.6) | 0.41% | — | Matrixaddons Easy InvoiceAIPHPAI | 21/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4. | |
| Aplazada | Media (5.9) | 25% | 💥 Exploit | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 11/11/2025 | 17/6/2026 | Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Aplazada | Alta (8.3) | 0.45% | — | Element Matrix-authentication-serviceAI | 16/10/2025 | 17/6/2026 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without… | |
| Aplazada | Media (5.5) | 0.26% | — | BlindmatrixAI | 15/10/2025 | 17/6/2026 | The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks. | |
| Aplazada | Media (6.4) | 0.41% | — | Matrix Javascript SDKAI | 14/10/2025 | 17/6/2026 | Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode… | |
| Aplazada | Alta (7.1) | 0.33% | — | MatrixAI | 2/10/2025 | 17/6/2026 | The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness. | |
| Aplazada | Alta (7.1) | 0.46% | — | Matrix SpecificationAI | 2/10/2025 | 17/6/2026 | The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution. | |
| Analizada | Crítica (9.8) | 3.5% | — | Swetrix | 17/9/2025 | 17/6/2026 | A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request. | |
| Aplazada | Baja (2.7) | 0.24% | — | Matrix Javascript SDKAI | 16/9/2025 | 17/6/2026 | Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue… |