Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.41% | — | Eaton Aspect EnterpriseAIEaton Nexus SeriesAIEaton Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Media (5.9) | 0.38% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Alta (7.5) | 0.69% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Alta (7.5) | 0.37% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Crítica (9.5) | 0.38% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Alta (7.5) | 0.46% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Alta (7) | 0.36% | — | Tibco Activematrix AdministratorAI | 21/5/2025 | 17/6/2026 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application. | |
| Aplazada | Baja (2) | 0.72% | — | TrixAI | 8/5/2025 | 17/6/2026 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session,… | |
| Aplazada | Media (6.5) | 0.31% | 💥 PoC | ITC Systems Multiplan Matrix OnecardAI | 24/4/2025 | 17/6/2026 | ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx. | |
| Aplazada | Crítica (9.2) | 0.92% | — | Formulatrix Rock Maker WEBAI | 21/4/2025 | 17/6/2026 | Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data… | |
| Aplazada | Baja (3.8) | 0.16% | — | Element WEBAIElement CallAIMatrix React SDKAI | 8/4/2025 | 17/6/2026 | Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call… | |
| Analizada | Alta (7.5) | 1.2% | — | Matrix Synapse | 27/3/2025 | 17/6/2026 | Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available. | |
| Analizada | Media (4.3) | 0.40% | — | Matrix IRC Bridge | 25/2/2025 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in… | |
| Analizada | Media (5.9) | 0.16% | — | Citrix Secure Access Client | 20/2/2025 | 17/6/2026 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac | |
| Analizada | Media (5.9) | 0.16% | — | Citrix Secure Access Client | 20/2/2025 | 17/6/2026 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac | |
| Analizada | Alta (8.8) | 13% | — | Citrix Netscaler AgentCitrix Netscaler Console | 20/2/2025 | 17/6/2026 | Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory… | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input. | |
| Modificada | Crítica (9.3) | 0.62% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 6/2/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.5) | 0.45% | — | Matrix-hookshotAI | 27/1/2025 | 17/6/2026 | matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot 5 version 5.4.1 or below, is configured with GitHub support, it is vulnerable to a Denial of Service (DoS) whereby it can crash on restart due to a missing check.… | |
| Analizada | Media (6.5) | 0.64% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbnail to invoke a different decoder in ImageMagick. In some… | |
| Analizada | Alta (7.5) | 0.76% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return large amounts of JSON back to MMR for parsing. In parsing, MMR can consume large amounts of memory and exhaust available… | |
| Analizada | Media (5.3) | 0.57% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fixed in MMR v1.3.8. Users are advised to upgrade. Restricting… | |
| Analizada | Alta (7.5) | 0.70% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary can induce it to download and cache large amounts of remote media files. MMR's typical operating environment uses… | |
| Analizada | Media (5.3) | 0.55% | — | T2bot Matrix-media-repo | 16/1/2025 | 17/6/2026 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then also becomes… |