Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.18%—Simopro Technology Winmatrix AgentAI16/4/202617/6/2026
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.
Pendiente de análisisAlta (8.7)0.38%—Tibco Activematrix BusinessworksAITibco Enterprise AdministratorAI24/3/202617/6/2026
Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.
Pendiente de análisisAlta (7.7)0.29%—Citrix Netscaler ADCAICitrix Netscaler GatewayAI23/3/202617/6/2026
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup
AnalizadaCrítica (9.3)4.0%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway23/3/202617/6/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
AplazadaBaja (2)0.33%—Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI12/3/202617/6/2026
A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AplazadaBaja (2)0.33%—Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI12/3/202617/6/2026
A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to…
AplazadaCrítica (9.2)0.29%—Element Server Suite Community EditionAIMatrix-toolsAIElement ESS Community Helm ChartAI12/2/202617/6/2026
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network…
AnalizadaAlta (7.7)4.7%—Inextrix Astpp11/2/202617/6/2026
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions…
AnalizadaAlta (8.7)0.60%—Inextrix Astpp11/2/202617/6/2026
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the…
AplazadaMedia (5.8)0.33%—Langsmith Python SDKAIMatrix Javascript SDKAI9/2/202617/6/2026
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive…
AplazadaMedia (6.8)0.16%—Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+122/1/202617/6/2026
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers…
AplazadaAlta (8.5)0.16%—Vb-audio MatrixAIVb-audio Matrix CoconutAI22/1/202617/6/2026
VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local privilege escalation vulnerability in the VBMatrix VAIO virtual audio driver (vbmatrixvaio64*_win10.sys). The driver allocates a 128-byte non-paged pool buffer and, upon receiving IOCTL 0x222060, maps…
AplazadaMedia (6.9)0.21%—Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+122/1/202617/6/2026
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers…
AplazadaMedia (6.9)0.18%—Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+122/1/202617/6/2026
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers…
AplazadaAlta (7.1)0.18%—Matrixaddons Easy InvoiceAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy Invoice easy-invoice allows DOM-Based XSS.This issue affects Easy Invoice: from n/a through <= 2.0.9.
AnalizadaBaja (1.3)0.41%—Matrix-rust-sdk9/12/202517/6/2026
matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join…
AplazadaMedia (6.6)0.41%—Matrixaddons Easy InvoiceAIPHPAI21/11/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.
AplazadaMedia (5.9)25%💥 ExploitCitrix Netscaler ADCAICitrix Netscaler GatewayAI11/11/202517/6/2026
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AplazadaAlta (8.3)0.45%—Element Matrix-authentication-serviceAI16/10/202517/6/2026
MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without…
AplazadaMedia (5.5)0.26%—BlindmatrixAI15/10/202517/6/2026
The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks.
AplazadaMedia (6.4)0.41%—Matrix Javascript SDKAI14/10/202517/6/2026
Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode…
AplazadaAlta (7.1)0.33%—MatrixAI2/10/202517/6/2026
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
AplazadaAlta (7.1)0.46%—Matrix SpecificationAI2/10/202517/6/2026
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
AnalizadaCrítica (9.8)3.5%—Swetrix17/9/202517/6/2026
A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request.
AplazadaBaja (2.7)0.24%—Matrix Javascript SDKAI16/9/202517/6/2026
Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue…