Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.87%—Matrixcomsec Cosec Vega Faxq Firmware25/10/202417/6/2026
This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this…
AplazadaAlta (8.7)0.66%—Matrix-react-sdkAI15/10/202417/6/2026
matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a…
AplazadaAlta (8.7)0.68%—Matrix-js-sdkAI15/10/202417/6/2026
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061) and is commonly used to share historical…
AnalizadaMedia (5.4)0.18%—Citrix Workspace11/9/202417/6/2026
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
AnalizadaAlta (7)0.25%—Citrix Workspace11/9/202417/6/2026
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
AnalizadaAlta (7.1)0.15%—Citrix Workspace10/9/202417/6/2026
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to…
AnalizadaMedia (4.3)0.30%—Matrix OLM22/8/202417/6/2026
An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AnalizadaMedia (5.3)0.54%—Matrix OLM22/8/202417/6/2026
An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AnalizadaMedia (5.3)0.45%—Matrix OLM22/8/202417/6/2026
An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that…
AplazadaMedia (5.3)0.46%—Flamix Bitrix24 AND Contact Form 7 IntegrationsAI21/8/202417/6/2026
The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.0. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the…
AnalizadaMedia (5.3)0.48%—Matrix Javascript SDK20/8/202417/6/2026
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but…
AplazadaMedia (6.5)0.52%—Basecamp TrixAI14/8/202417/6/2026
The Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in place for GHSA-qjqp-xr96-cj99. In pull request 1149, sanitation was added for Trix attachments with a `text/html` content type. However, Trix only checks the content type on the…
AnalizadaMedia (6.5)0.43%—Matrix-react-sdk6/8/202417/6/2026
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was…
ModificadaCrítica (9.8)0.17%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
ModificadaAlta (7.5)0.35%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
ModificadaMedia (6.1)0.25%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)0.40%—Matrix-globalservices Tafnit30/7/202417/6/2026
Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties
ModificadaCrítica (9.8)0.69%—Simopro Technology Winmatrix329/7/202417/6/2026
The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
ModificadaCrítica (9.8)0.69%—Simopro Technology Winmatrix329/7/202417/6/2026
The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
AplazadaMedia (5.4)0.28%—Matrix-rust-sdk Matrix-sdk-cryptoAI18/7/202417/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result return a value…
AnalizadaAlta (7.3)0.22%—Citrix Uberagent12/7/202417/6/2026
Privilege escalation in uberAgent
AnalizadaAlta (8.5)0.39%—Citrix Workspace10/7/202417/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
AnalizadaAlta (7.1)0.74%—Citrix Netscaler AgentCitrix Netscaler ConsoleCitrix Netscaler SDX10/7/202417/6/2026
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
AnalizadaAlta (8.5)0.21%—Citrix Virtual Apps AND Desktops10/7/202417/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS
AnalizadaMedia (4.8)0.24%—Citrix Provisioning10/7/202417/6/2026
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
Orbitaley — Vulnerabilidades