Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.88% | — | Matrix IRC Bridge | 13/9/2022 | 17/6/2026 | matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc perform parsing of such modes incorrectly,… | |
| Modificada | Media (5.3) | 0.36% | — | Matrix Dendrite | 12/9/2022 | 17/6/2026 | Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note… | |
| Modificada | Media (5.3) | 0.57% | — | Squiz Matrix | 6/9/2022 | 17/6/2026 | Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about… | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Synapse | 2/9/2022 | 17/6/2026 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In… | |
| Modificada | Alta (8.8) | 0.82% | — | Matrix DendriteGomatrixserverlib | 19/8/2022 | 17/6/2026 | gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to… | |
| Modificada | Media (6.5) | 0.52% | — | Jenkins Matrix Reloaded | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Matrix Reloaded | 30/6/2022 | 17/6/2026 | Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | |
| Modificada | Media (6.5) | 1.7% | — | Matrix SynapseFedoraproject Fedora | 28/6/2022 | 17/6/2026 | Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem,… | |
| Modificada | Alta (8.8) | 1.0% | — | Matrix IRC Bridge | 5/5/2022 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2. Refrain from replying to messages… | |
| Modificada | Media (6.5) | 1.1% | — | Twistedmatrix TreqDebian Linux | 1/2/2022 | 17/6/2026 | treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies").… | |
| Modificada | Media (5.4) | 82% | — | Jenkins Matrix ProjectOracle Communications Cloud Native Core Automated Test Suite | 12/1/2022 | 17/6/2026 | Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | |
| Modificada | Crítica (9.8) | 2.0% | — | Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+2 | 14/12/2021 | 17/6/2026 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to… | |
| Modificada | Alta (7.5) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 23/11/2021 | 17/6/2026 | Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the affected endpoint. The last 2 directories… | |
| Modificada | Media (5.9) | 0.66% | — | Matrix ElementMatrix-android-sdk2 | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by… | |
| Modificada | Media (5.9) | 0.66% | — | Matrix Javascript SDK | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in… | |
| Modificada | Baja (3.1) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 31/8/2021 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms with `shared` history visibility.… | |
| Modificada | Baja (3.1) | 0.90% | — | Matrix SynapseFedoraproject Fedora | 31/8/2021 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where the vulnerable homeserver is in the room… | |
| Modificada | Alta (7.5) | 1.3% | — | Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux | 18/7/2021 | 17/6/2026 | uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality). | |
| Modificada | Media (4.9) | 0.94% | — | Matrix-appservice-bridge | 16/6/2021 | 17/6/2026 | Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it… | |
| Modificada | Crítica (9.8) | 4.3% | — | Matrix OLM | 16/6/2021 | 17/6/2026 | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations. | |
| Modificada | Alta (7.8) | 0.37% | — | Matrix-react-sdk Project Matrix-react-sdk | 17/5/2021 | 17/6/2026 | Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab.… | |
| Modificada | Media (5.3) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 11/5/2021 | 17/6/2026 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against… | |
| Modificada | Media (6.5) | 1.0% | — | Matrix-media-repo Project Matrix-media-repo | 19/4/2021 | 17/6/2026 | matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user could upload a relatively small image in terms of file size, using… | |
| Modificada | Media (5.7) | 0.93% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d. | |
| Modificada | Media (6.5) | 1.2% | — | Matrix Sydent | 15/4/2021 | 17/6/2026 | Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port… |