Where
-Infinity
0

pip/matrix-synapseSynapse pagination denial of service

Risk 23
Severity
5.1
First published (updated )

pip/matrix-synapseSynapse CPU starvation (Denial of Service)

Risk 37
Severity
6.8
First published (updated )

Element Matrix Authentication ServiceMatrix Authentication Service account password can be changed using an authenticated session without supplying the current password

Risk 69
Severity
8.3
First published (updated )

Element WebIn Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left

Risk 18
Severity
2.7
First published (updated )

Element Element X AndroidElement X Android vulnerable to loading malicious web pages via received intent

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Element Element WebElement Web could load a malicious instance of Element Call leaking media encryption keys

Risk 20
Severity
3.8
EPSS
0.02%
First published (updated )

Element Element X iOSElement X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Call

Risk 19
Severity
5.3
EPSS
0.02%
First published (updated )

Element Element X AndroidElement X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Call

Risk 19
Severity
5.3
EPSS
0.02%
First published (updated )

Element Element AndroidElement Android PIN autologout bypass

Risk 23
Severity
5.1
EPSS
0.02%
First published (updated )

Element Element WebElement allows a malicious homeserver can modify events leading to unrenderable events or rooms

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Element Element WebElement's thumbnails can be abused to misrepresent the content of an attachment

Risk 19
Severity
3.5
First published (updated )

Element Element WebElement Web vulnerable to potential exposure of access token via authenticated media

Risk 54
Severity
7
First published (updated )

Element DesktopElement Desktop vulnerable to potential exposure of access token via authenticated media

Risk 54
Severity
7
First published (updated )

Element Element AndroidElement Android can be asked to share internal files.

Risk 15
Severity
4
EPSS
0.04%
First published (updated )

Element Element AndroidElement Android Intent Redirection

Risk 54
Severity
8.4
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Element Element Iphone OsElement iOS is vulnerable due to missing decoration for events decrypted with untrusted Megolm sessions

Risk 40
Severity
6.5
First published (updated )

Element Desktop Node.jsRemote program execution with user interaction

Risk 77
Severity
8.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203