Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.7)0.41%—Element WEBAIElement DesktopAIMatrix React SDKAI16/9/20251/10/2026
Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room.…
AplazadaBaja (2.7)0.40%—Matrix-sdk-baseAI11/9/202517/6/2026
matrix-sdk-base is the base component to build a Matrix client library. In matrix-sdk-base before 0.14.1, calling the `RoomMember::normalized_power_level()` method can cause a panic if a room member has a power level of `Int::Min`. The issue is fixed in matrix-sdk-base 0.14.1. The affected method isn’t used…
AplazadaMedia (6.5)0.17%—Matrixaddons Document EngineAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Document Engine document-engine allows Stored XSS.This issue affects Document Engine: from n/a through <= 1.2.
AplazadaAlta (8.7)3.3%—Citrix Netscaler ADCAICitrix Netscaler GatewayAI26/8/202517/6/2026
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access
AnalizadaAlta (8.8)8.2%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway26/8/202517/6/2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it
AnalizadaCrítica (9.2)20%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway26/8/202517/6/2026
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB…
AnalizadaMedia (6.5)4.8%—Twistedmatrix Twistedweb5/8/202517/6/2026
A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker…
AplazadaMedia (6.1)0.30%—Simopro Technology Winmatrix3 WEBAI21/7/202517/6/2026
WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AplazadaAlta (7.1)0.43%—Simopro Technology Winmatrix3 WEBAI21/7/202517/6/2026
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AplazadaCrítica (9.3)0.43%—Simopro Technology Winmatrix3 WEBAI21/7/202517/6/2026
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AplazadaAlta (8.6)0.55%—Simopro Technology Winmatrix3AI21/7/202517/6/2026
WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaCrítica (9.3)0.77%—Simopro Technology Winmatrix3AI21/7/202517/6/2026
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.
AplazadaMedia (5.2)0.29%—Matrix Rust SDKAI10/7/202517/6/2026
The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the EventCache::find_event_with_relations method of matrix-sdk 0.11 and 0.12 allows malicious room members to execute arbitrary SQL commands in Matrix clients that directly pass…
AnalizadaAlta (7.3)0.24%💥 PoCCitrix Virtual Apps AND Desktops8/7/202517/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS
AnalizadaCrítica (9.2)11%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway25/6/202517/6/2026
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AplazadaAlta (8.8)0.28%—VisionatrixAIComfyuiAITiangolo FastapiAI23/6/202517/6/2026
Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the…
AplazadaMedia (6.6)12%—Aviatrix ControllerAI23/6/202517/6/2026
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
AplazadaAlta (7.8)0.48%—Aviatrix ControllerAI23/6/202517/6/2026
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
AnalizadaAlta (7.3)0.13%—Citrix Workspace17/6/202517/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
AnalizadaAlta (8.6)0.15%—Citrix Secure Access Client17/6/202517/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows
AnalizadaCrítica (9.3)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/20254/8/2026
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AnalizadaAlta (8.7)6.2%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/202517/6/2026
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
AnalizadaMedia (6.9)11%—Citrix Netscaler ConsoleCitrix Netscaler SDX17/6/202517/6/2026
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
AplazadaCrítica (9.4)0.22%—Cyclone Matrix TRF Smart Keyless Entry SystemAIKIA SolutoAI13/6/202517/6/2026
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack confirmed on other KIA Models in Ecuador.
AplazadaMedia (4.9)0.37%—Matrix-rust-sdk Matrix-sdk-cryptoAIMatrix-rust-sdkAI10/6/202517/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the…
Orbitaley — Vulnerabilidades