Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-45078Medium· 5.5Synapse CPU starvation (Denial of Service)
CVE-2026-45076MediumSynapse pagination Denial of Service
CVE-2025-61672MediumSynapse's invalid device keys degrade federation functionality
CVE-2025-30355High· 7.1Synapse vulnerable to federation denial of service via malformed events
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion
CVE-2024-52815HighSynapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-53867Medium· 4.3Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-31208Medium· 6.5Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
CVE-2023-45129Medium· 4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-42453Low· 3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-41335Low· 3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-32682Medium· 5.4Synapse has improper checks for deactivated users during login
CVE-2018-10657High· 7.5⚠ Exploited0dayMatrix Synapse DoS
CVE-2018-12291High· 7.5Matrix Synapse Security Filtering Flaw
CVE-2018-16515High· 8.8Matrix Synapse Improper Signature Validation
CVE-2018-12423High· 7.5Matrix Synapse Authorization Error
CVE-2022-41952Medium· 5.3Uncontrolled Resource Consumption in Matrix Synapse
CVE-2021-41281High· 7.5Path traversal in Matrix Synapse
CVE-2021-39163Low· 3.1Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
CVE-2021-39164Low· 3.1Improper authorisation of members discloses room membership to non-members
CVE-2021-29471Low· 3.7Denial of service attack via push rule patterns in matrix-synapse
CVE-2021-21394Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21393Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.