Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.41%—Eaton Aspect EnterpriseAIEaton Nexus SeriesAIEaton Matrix SeriesAI22/5/202517/6/2026
Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaMedia (5.9)0.38%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaAlta (7.5)0.69%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaAlta (7.5)0.37%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaCrítica (9.5)0.38%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaAlta (7.5)0.46%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaAlta (7)0.36%—Tibco Activematrix AdministratorAI21/5/202517/6/2026
Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.
AplazadaBaja (2)0.72%—TrixAI8/5/202517/6/2026
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session,…
AplazadaMedia (6.5)0.31%💥 PoCITC Systems Multiplan Matrix OnecardAI24/4/202517/6/2026
ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.
AplazadaCrítica (9.2)0.92%—Formulatrix Rock Maker WEBAI21/4/202517/6/2026
Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data…
AplazadaBaja (3.8)0.16%—Element WEBAIElement CallAIMatrix React SDKAI8/4/202517/6/2026
Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call…
AnalizadaAlta (7.5)1.2%—Matrix Synapse27/3/202517/6/2026
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
AnalizadaMedia (4.3)0.40%—Matrix IRC Bridge25/2/202517/6/2026
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in…
AnalizadaMedia (5.9)0.16%—Citrix Secure Access Client20/2/202517/6/2026
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
AnalizadaMedia (5.9)0.16%—Citrix Secure Access Client20/2/202517/6/2026
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
AnalizadaAlta (8.8)13%—Citrix Netscaler AgentCitrix Netscaler Console20/2/202517/6/2026
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
AplazadaMedia (5.5)0.27%—Effectmatrix Total Video Converter Command LineAI13/2/202517/6/2026
A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory…
AplazadaMedia (5.5)0.27%—Effectmatrix Total Video Converter Command LineAI13/2/202517/6/2026
A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input.
ModificadaCrítica (9.3)0.62%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+156/2/202517/6/2026
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
AplazadaMedia (6.5)0.45%—Matrix-hookshotAI27/1/202517/6/2026
matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot 5 version 5.4.1 or below, is configured with GitHub support, it is vulnerable to a Denial of Service (DoS) whereby it can crash on restart due to a missing check.…
AnalizadaMedia (6.5)0.64%—T2bot Matrix-media-repo16/1/202517/6/2026
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbnail to invoke a different decoder in ImageMagick. In some…
AnalizadaAlta (7.5)0.76%—T2bot Matrix-media-repo16/1/202517/6/2026
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return large amounts of JSON back to MMR for parsing. In parsing, MMR can consume large amounts of memory and exhaust available…
AnalizadaMedia (5.3)0.57%—T2bot Matrix-media-repo16/1/202517/6/2026
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fixed in MMR v1.3.8. Users are advised to upgrade. Restricting…
AnalizadaAlta (7.5)0.70%—T2bot Matrix-media-repo16/1/202517/6/2026
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary can induce it to download and cache large amounts of remote media files. MMR's typical operating environment uses…
AnalizadaMedia (5.3)0.55%—T2bot Matrix-media-repo16/1/202517/6/2026
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then also becomes…