Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.83%—Matrix-js-sdkAI12/11/202417/6/2026
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver.…
AplazadaCrítica (9.8)0.98%💥 PoCUdit Rawat Exam MatrixAI29/10/202417/6/2026
Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.
AnalizadaCrítica (9.3)0.87%—Matrixcomsec Cosec Vega Faxq Firmware25/10/202417/6/2026
This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this…
AplazadaAlta (8.7)0.66%—Matrix-react-sdkAI15/10/202417/6/2026
matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a…
AplazadaAlta (8.7)0.68%—Matrix-js-sdkAI15/10/202417/6/2026
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061) and is commonly used to share historical…
AnalizadaMedia (4.3)0.30%—Matrix OLM22/8/202417/6/2026
An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AnalizadaMedia (5.3)0.54%—Matrix OLM22/8/202417/6/2026
An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AnalizadaMedia (5.3)0.45%—Matrix OLM22/8/202417/6/2026
An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that…
AnalizadaMedia (5.3)0.48%—Matrix Javascript SDK20/8/202417/6/2026
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but…
AnalizadaMedia (6.5)0.43%—Matrix-react-sdk6/8/202417/6/2026
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was…
ModificadaCrítica (9.8)0.17%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
ModificadaAlta (7.5)0.35%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
ModificadaMedia (6.1)0.25%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)0.40%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties
ModificadaCrítica (9.8)0.69%—Simopro Technology Winmatrix329/7/202417/6/2026
The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
ModificadaCrítica (9.8)0.69%—Simopro Technology Winmatrix329/7/202417/6/2026
The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
AplazadaMedia (5.4)0.28%—Matrix-rust-sdk Matrix-sdk-cryptoAI18/7/202417/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result return a value…
AplazadaMedia (4.3)0.50%—Matrix Appservice-ircAI5/7/202417/6/2026
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether…
ModificadaCrítica (9.4)19%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
ModificadaCrítica (9.4)17%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
AnalizadaAlta (8.7)1.5%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+91/7/202417/6/2026
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
AplazadaMedia (5.5)0.19%—Matrix-sdk-cryptoAI14/5/202417/6/2026
The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in…
AnalizadaMedia (6.5)1.5%—Matrix SynapseFedoraproject Fedora23/4/202417/6/2026
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the…
AplazadaMedia (4.3)0.45%—Matrix Appservice-ircAI12/4/202417/6/2026
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don't have access to. As a precondition to the attack, the malicious user…
ModificadaMedia (4.3)0.69%—Jenkins Matrix Project24/1/202417/6/2026
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
Orbitaley — Vulnerabilidades