Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.41% | — | Element WEBAIElement DesktopAIMatrix React SDKAI | 16/9/2025 | 1/10/2026 | Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room.… | |
| Aplazada | Baja (2.7) | 0.40% | — | Matrix-sdk-baseAI | 11/9/2025 | 17/6/2026 | matrix-sdk-base is the base component to build a Matrix client library. In matrix-sdk-base before 0.14.1, calling the `RoomMember::normalized_power_level()` method can cause a panic if a room member has a power level of `Int::Min`. The issue is fixed in matrix-sdk-base 0.14.1. The affected method isn’t used… | |
| Aplazada | Media (6.5) | 0.17% | — | Matrixaddons Document EngineAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Document Engine document-engine allows Stored XSS.This issue affects Document Engine: from n/a through <= 1.2. | |
| Aplazada | Alta (8.7) | 3.3% | — | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 26/8/2025 | 17/6/2026 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access | |
| Analizada | Alta (8.8) | 8.2% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it | |
| Analizada | Crítica (9.2) | 20% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB… | |
| Analizada | Media (6.5) | 4.8% | — | Twistedmatrix Twistedweb | 5/8/2025 | 17/6/2026 | A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker… | |
| Aplazada | Media (6.1) | 0.30% | — | Simopro Technology Winmatrix3 WEBAI | 21/7/2025 | 17/6/2026 | WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Aplazada | Alta (7.1) | 0.43% | — | Simopro Technology Winmatrix3 WEBAI | 21/7/2025 | 17/6/2026 | WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Simopro Technology Winmatrix3 WEBAI | 21/7/2025 | 17/6/2026 | WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Alta (8.6) | 0.55% | — | Simopro Technology Winmatrix3AI | 21/7/2025 | 17/6/2026 | WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Crítica (9.3) | 0.77% | — | Simopro Technology Winmatrix3AI | 21/7/2025 | 17/6/2026 | WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents. | |
| Aplazada | Media (5.2) | 0.29% | — | Matrix Rust SDKAI | 10/7/2025 | 17/6/2026 | The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the EventCache::find_event_with_relations method of matrix-sdk 0.11 and 0.12 allows malicious room members to execute arbitrary SQL commands in Matrix clients that directly pass… | |
| Analizada | Alta (7.3) | 0.24% | 💥 PoC | Citrix Virtual Apps AND Desktops | 8/7/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS | |
| Analizada | Crítica (9.2) | 11% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 25/6/2025 | 17/6/2026 | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Aplazada | Alta (8.8) | 0.28% | — | VisionatrixAIComfyuiAITiangolo FastapiAI | 23/6/2025 | 17/6/2026 | Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the… | |
| Aplazada | Media (6.6) | 12% | — | Aviatrix ControllerAI | 23/6/2025 | 17/6/2026 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames | |
| Aplazada | Alta (7.8) | 0.48% | — | Aviatrix ControllerAI | 23/6/2025 | 17/6/2026 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN | |
| Analizada | Alta (7.3) | 0.13% | — | Citrix Workspace | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Alta (8.6) | 0.15% | — | Citrix Secure Access Client | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows | |
| Analizada | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 4/8/2026 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Alta (8.7) | 6.2% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 17/6/2026 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway | |
| Analizada | Media (6.9) | 11% | — | Citrix Netscaler ConsoleCitrix Netscaler SDX | 17/6/2025 | 17/6/2026 | Arbitrary file read in NetScaler Console and NetScaler SDX (SVM) | |
| Aplazada | Crítica (9.4) | 0.22% | — | Cyclone Matrix TRF Smart Keyless Entry SystemAIKIA SolutoAI | 13/6/2025 | 17/6/2026 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack confirmed on other KIA Models in Ecuador. | |
| Aplazada | Media (4.9) | 0.37% | — | Matrix-rust-sdk Matrix-sdk-cryptoAIMatrix-rust-sdkAI | 10/6/2025 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the… |