Vendor
high
advisory
Cross-Site Scripting Vulnerability in Element maps-ng
1 CVEA stored cross-site scripting (XSS) vulnerability in the si-map component of Element maps-ng allows unauthenticated attackers to execute arbitrary scripts in a victim's browser via crafted map pin tooltips.
maps-ng
xss
web-vulnerability
patch-management
1c
medium
advisory
Synapse CPU Starvation Denial of Service Vulnerability
2 rules 1 TTP 1 IOCA denial-of-service vulnerability exists in Synapse where local authenticated users can cause CPU starvation, leading to request failures for other users (CVE-2026-45078).
matrix-synapse
denial-of-service
synapse
cpu-starvation
2r
1t
1i