Where
-Infinity
0

rust/matrix-sdk-basematrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values

Risk 43
Severity
7.5
First published (updated )

matrix Matrix specificationThe Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution befor…

Risk 50
Severity
7.1
First published (updated )

matrix Matrix specificationThe Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event unique…

Risk 48
Severity
7.1
First published (updated )

matrix Javascript SDKmatrix-js-sdk has insufficient validation when considering a room to be upgraded by another

Risk 18
Severity
2.7
First published (updated )

ASPECT ASPECT-EnterpriseSQL Injection 2nd Order

Risk 81
Severity
9.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ASPECT ASPECT-EnterpriseSensitive Information disclosed in log files

Risk 35
Severity
6.9
First published (updated )

ASPECT ASPECT-EnterpriseOne way hash with predictable salt

Risk 58
Severity
7.6
First published (updated )

ASPECT ASPECT-EnterpriseInsecure Permissions

Risk 47
Severity
7.3
First published (updated )

ASPECT ASPECT-EnterpriseExternal System or Configuration Control

Risk 50
Severity
7.1
First published (updated )

synapse SynapseSynapse vulnerable to federation denial of service via malformed events

Risk 31
Severity
7.5
EPSS
0.38%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/matrix-appservice-ircMatrix IRC Bridge allows IRC command injection to own puppeted user

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

matrix hookshotmatrix-hookshot has a Potential Denial of Service when Hookshot is configured with GitHub support

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )

ABB ASPECT - EnterpriseForce Change of Default Credentials

Risk 87
Severity
10
First published (updated )

ABB Aspect-ent-2 Firmwareoff-by-one-error

Risk 86
Severity
9.8
First published (updated )

ABB Aspect-ent-2 FirmwareDefault Credentials

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ABB Aspect-ent-12 FirmwareData Validation / Sanitization

Risk 95
Severity
10
First published (updated )

ABB Aspect-ent-12 FirmwareService Control

Risk 57
Severity
8.8
First published (updated )

ABB Aspect-ent-2 FirmwarePHP Session Fixation

Risk 73
Severity
10
First published (updated )

ABB Aspect-ent-2 FirmwareSSRF Server Side Request Forgery

Risk 82
Severity
9.9
First published (updated )

pip/matrix-synapseSynapse unauthenticated writes to the media repository allow planting of problematic content

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/matrix-synapseSynapse denial of service through media disk space consumption

Risk 45
Severity
7.5
First published (updated )

pip/matrix-synapseSynapse allows unsupported content types to lead to memory exhaustion

Risk 45
Severity
8.2
First published (updated )

pip/matrix-synapseSynapse allows a a malformed invite to break the invitee's `/sync`

Risk 49
Severity
8.7
First published (updated )

pip/matrix-synapseSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Risk 69
Severity
9.1
First published (updated )

matrix libolmAn issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cac…

Risk 32
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

matrix libolmAn issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use o…

Risk 32
Severity
5.3
First published (updated )

matrix libolmAn issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due…

Risk 22
Severity
4.3
First published (updated )

npm/matrix-js-sdkA room with itself as a its predecessor will freeze matrix-js-sdk

Risk 28
Severity
5.3
First published (updated )

npm/matrix-react-sdkURL preview setting for a room is controllable by the homeserver in matrix-react-sdk

Risk 45
Severity
7.7
First published (updated )

Fedoraproject FedoraSynapse's V2 state resolution weakness allows DoS from remote room members

Risk 28
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203