Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.36% | — | Tibco Activematrix AdministratorAI | 21/5/2025 | 17/6/2026 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application. | |
| Aplazada | Media (6.5) | 0.31% | 💥 PoC | ITC Systems Multiplan Matrix OnecardAI | 24/4/2025 | 17/6/2026 | ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx. | |
| Aplazada | Baja (3.8) | 0.16% | — | Element WEBAIElement CallAIMatrix React SDKAI | 8/4/2025 | 17/6/2026 | Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call… | |
| Analizada | Alta (7.5) | 1.2% | — | Matrix Synapse | 27/3/2025 | 17/6/2026 | Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available. | |
| Analizada | Media (4.3) | 0.40% | — | Matrix IRC Bridge | 25/2/2025 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in… | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory… | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input. | |
| Modificada | Crítica (9.3) | 0.62% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 6/2/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.5) | 0.45% | — | Matrix-hookshotAI | 27/1/2025 | 17/6/2026 | matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot 5 version 5.4.1 or below, is configured with GitHub support, it is vulnerable to a Denial of Service (DoS) whereby it can crash on restart due to a missing check.… | |
| Analizada | Media (6.5) | 0.64% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbnail to invoke a different decoder in ImageMagick. In some… | |
| Analizada | Alta (7.5) | 0.76% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return large amounts of JSON back to MMR for parsing. In parsing, MMR can consume large amounts of memory and exhaust available… | |
| Analizada | Media (5.3) | 0.57% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fixed in MMR v1.3.8. Users are advised to upgrade. Restricting… | |
| Analizada | Alta (7.5) | 0.70% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary can induce it to download and cache large amounts of remote media files. MMR's typical operating environment uses… | |
| Analizada | Media (5.3) | 0.55% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then also becomes… | |
| Aplazada | Media (4.3) | 0.34% | — | GomatrixserverlibAI | 16/1/2025 | 17/6/2026 | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local… | |
| Aplazada | Media (4.3) | 0.48% | — | Matrix-rust-sdk Matrix-sdk-cryptoAI | 7/1/2025 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK… | |
| Analizada | Media (6.7) | 0.17% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Analizada | Crítica (9.8) | 0.76% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Analizada | Alta (8.7) | 0.50% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 5/12/2024 | 17/6/2026 | Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure. Affected products: | |
| Analizada | Crítica (9.3) | 1.1% | 💥 Exploit | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 5/12/2024 | 17/6/2026 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products: | |
| Analizada | Alta (8.7) | 0.40% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 5/12/2024 | 17/6/2026 | Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure. Affected products: | |
| Aplazada | Crítica (9.3) | 0.42% | — | ABB AspectAIABB Nexus SeriesAIABB Matrix SeriesAI | 5/12/2024 | 17/6/2026 | Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials. Affected products: | |
| Analizada | Alta (8.8) | 0.39% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 5/12/2024 | 17/6/2026 | Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: | |
| Analizada | Crítica (9.3) | 0.45% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 5/12/2024 | 17/6/2026 | Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: | |
| Analizada | Crítica (9.3) | 1.8% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/12/2024 | 17/6/2026 | Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products: |