Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langsmith Python SDKAIMatrix Javascript SDKAI | 23/4/2026 | 17/6/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces… | |
| Aplazada | Media (5.8) | 0.33% | — | Langsmith Python SDKAIMatrix Javascript SDKAI | 9/2/2026 | 17/6/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive… | |
| Aplazada | Media (6.4) | 0.41% | — | Matrix Javascript SDKAI | 14/10/2025 | 17/6/2026 | Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode… | |
| Analizada | Media (6.5) | 0.35% | — | Parseplatform Parse Javascript SDK | 24/9/2025 | 17/6/2026 | parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the… | |
| Aplazada | Baja (2.7) | 0.24% | — | Matrix Javascript SDKAI | 16/9/2025 | 17/6/2026 | Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue… | |
| Analizada | Media (5.2) | 0.13% | — | Google Firebase Javascript SDK | 18/11/2024 | 17/6/2026 | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it… | |
| Analizada | Media (5.3) | 0.48% | — | Matrix Javascript SDK | 20/8/2024 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but… | |
| Modificada | Media (5.3) | 0.54% | — | Matrix Javascript SDK | 14/4/2023 | 17/6/2026 | matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be… | |
| Modificada | Alta (8.2) | 1.2% | — | Matrix Javascript SDK | 28/3/2023 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the… | |
| Modificada | Media (5.3) | 0.94% | — | Matrix Javascript SDK | 28/3/2023 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the… | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Javascript SDK | 29/9/2022 | 17/6/2026 | Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’… | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker… | |
| Modificada | Alta (7.5) | 1.3% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.… | |
| Modificada | Media (5.3) | 1.4% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be… | |
| Modificada | Crítica (9.8) | 1.9% | — | Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+2 | 14/12/2021 | 17/6/2026 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to… | |
| Modificada | Media (5.9) | 0.66% | — | Matrix Javascript SDK | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in… |