Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.73%—MatrixsslRambus TLS Toolkit22/12/202317/6/2026
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded.…
ModificadaAlta (8.8)0.29%—Nkb-bd Preloader Matrix18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lukman Nakib Preloader Matrix.This issue affects Preloader Matrix: from n/a through 2.0.1.
ModificadaMedia (5.3)0.90%—Matrix SynapseFedoraproject Fedora31/10/202317/6/2026
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a…
ModificadaMedia (4.9)1.2%—Matrix SynapseFedoraproject Fedora10/10/202317/6/2026
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to…
ModificadaCrítica (9)0.32%—Matrix Hookshot27/9/202317/6/2026
matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `generic.allowJsTransformationFunctions` in their config), may be vulnerable to an attack where it is possible to break out of the `vm2` sandbox…
ModificadaMedia (4.3)0.78%—Matrix SynapseFedoraproject Fedora27/9/202317/6/2026
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show…
ModificadaBaja (3.7)0.39%—Matrix SynapseFedoraproject Fedora27/9/202317/6/2026
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the…
ModificadaAlta (7.2)1.2%—Bosch RTS Vlink Virtual Matrix18/9/202317/6/2026
A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.
ModificadaMedia (5.4)0.52%—Turt2live Matrix-media-repo8/9/202317/6/2026
matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inline` upon download. This vulnerability could be leveraged to…
ModificadaBaja (3.7)0.60%—Matrix IRC Bridge4/8/202317/6/2026
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the…
ModificadaMedia (6.5)0.47%—Matrix-appservice-bridge4/8/202317/6/2026
matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impersonate users when using the provisioning API. The library does not check that the…
ModificadaCrítica (9.8)0.86%—Matrix IRC Bridge4/8/202317/6/2026
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are…
ModificadaMedia (5.3)0.27%—Matrix Sydent4/8/202317/6/2026
Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack. Attackers with privileged access to the…
ModificadaAlta (7.5)0.60%—Intergard Smartgard Silver With Matrix Keyboard19/7/202317/6/2026
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Query Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high.…
ModificadaAlta (7.5)0.41%—Intergard Smartgard Silver With Matrix Keyboard19/7/202317/6/2026
A vulnerability was found in Intergard SGS 8.7.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information in memory. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (7.5)0.49%—Intergard Smartgard Silver With Matrix Keyboard19/7/202317/6/2026
A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Password Change Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be launched remotely. The complexity of an attack is…
ModificadaMedia (6.5)0.99%—Intergard Smartgard Silver With Matrix Keyboard19/7/202317/6/2026
A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.89%—Intergard Smartgard Silver With Matrix Keyboard19/7/202317/6/2026
A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is…
ModificadaMedia (5.4)0.45%—Matrix-react-sdk Project Matrix-react-sdk18/7/202317/6/2026
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored Cross site scripting (XSS). Since the Export Chat feature generates a separate…
ModificadaCrítica (9.8)0.76%—Game Result Matrix System Project Game Result Matrix System23/6/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affects an unknown part of the file /dipam/athlete-profile.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack…
ModificadaMedia (6.1)0.57%—Game Result Matrix System Project Game Result Matrix System23/6/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Game Result Matrix System 1.0. Affected by this issue is some unknown functionality of the file /dipam/save-delegates.php of the component GET Parameter Handler. The manipulation of the argument del_name leads to cross site…
ModificadaMedia (5.4)0.60%—Matrix Synapse6/6/202317/6/2026
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the…
ModificadaMedia (5.4)0.75%—Matrix Synapse6/6/202317/6/2026
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are true: 1. JSON Web Tokens are enabled for login via the `jwt_config.enabled`…
ModificadaCrítica (9.8)1.4%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-12 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/6/202317/6/2026
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021,…
ModificadaCrítica (9.8)0.37%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-12 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/6/202317/6/2026
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021,…
Orbitaley — Vulnerabilidades