Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.83% | — | Matrix-js-sdkAI | 12/11/2024 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver.… | |
| Aplazada | Crítica (9.8) | 0.98% | 💥 PoC | Udit Rawat Exam MatrixAI | 29/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5. | |
| Analizada | Crítica (9.3) | 0.87% | — | Matrixcomsec Cosec Vega Faxq Firmware | 25/10/2024 | 17/6/2026 | This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this… | |
| Aplazada | Alta (8.7) | 0.66% | — | Matrix-react-sdkAI | 15/10/2024 | 17/6/2026 | matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a… | |
| Aplazada | Alta (8.7) | 0.68% | — | Matrix-js-sdkAI | 15/10/2024 | 17/6/2026 | matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061) and is commonly used to share historical… | |
| Analizada | Media (4.3) | 0.30% | — | Matrix OLM | 22/8/2024 | 17/6/2026 | An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Analizada | Media (5.3) | 0.54% | — | Matrix OLM | 22/8/2024 | 17/6/2026 | An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Analizada | Media (5.3) | 0.45% | — | Matrix OLM | 22/8/2024 | 17/6/2026 | An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that… | |
| Analizada | Media (5.3) | 0.48% | — | Matrix Javascript SDK | 20/8/2024 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but… | |
| Analizada | Media (6.5) | 0.43% | — | Matrix-react-sdk | 6/8/2024 | 17/6/2026 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was… | |
| Modificada | Crítica (9.8) | 0.17% | — | Matrix-globalservices Tafnit | 30/7/2024 | 17/6/2026 | Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File | |
| Modificada | Alta (7.5) | 0.35% | — | Matrix-globalservices Tafnit | 30/7/2024 | 17/6/2026 | Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy | |
| Modificada | Media (6.1) | 0.25% | — | Matrix-globalservices Tafnit | 30/7/2024 | 17/6/2026 | Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 0.40% | — | Matrix-globalservices Tafnit | 30/7/2024 | 17/6/2026 | Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties | |
| Modificada | Crítica (9.8) | 0.69% | — | Simopro Technology Winmatrix3 | 29/7/2024 | 17/6/2026 | The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. | |
| Modificada | Crítica (9.8) | 0.69% | — | Simopro Technology Winmatrix3 | 29/7/2024 | 17/6/2026 | The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (5.4) | 0.28% | — | Matrix-rust-sdk Matrix-sdk-cryptoAI | 18/7/2024 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result return a value… | |
| Aplazada | Media (4.3) | 0.50% | — | Matrix Appservice-ircAI | 5/7/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether… | |
| Modificada | Crítica (9.4) | 19% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely | |
| Modificada | Crítica (9.4) | 17% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized | |
| Analizada | Alta (8.7) | 1.5% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+9 | 1/7/2024 | 17/6/2026 | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | |
| Aplazada | Media (5.5) | 0.19% | — | Matrix-sdk-cryptoAI | 14/5/2024 | 17/6/2026 | The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in… | |
| Analizada | Media (6.5) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 23/4/2024 | 17/6/2026 | Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the… | |
| Aplazada | Media (4.3) | 0.45% | — | Matrix Appservice-ircAI | 12/4/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don't have access to. As a precondition to the attack, the malicious user… | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Matrix Project | 24/1/2024 | 17/6/2026 | Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers. |