Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.49% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (7.2) | 0.49% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (8.3) | 0.23% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (8.3) | 0.23% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Media (5.3) | 0.37% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and… | |
| Analizada | Media (5.3) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and… | |
| Analizada | Media (5.3) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and… | |
| Analizada | Alta (7.1) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Alta (7.1) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Media (6) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 (… | |
| Analizada | Alta (7.5) | 0.47% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later | |
| Analizada | Alta (7.5) | 0.47% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later | |
| Aplazada | Alta (8.5) | 0.51% | 💥 Exploit | FTP Synchronizer ProfessionalAI | 21/8/2025 | 16/6/2026 | A stack-based buffer overflow exists in FTP Synchronizer Professional <= v4.0.73.274. When the client connects to an FTP server and issues a LIST command—typically during sync preview or profile creation—the server’s response containing an overly long filename triggers a buffer overflow. This results in the corruption… | |
| Aplazada | Media (5.9) | 0.22% | — | Keeross Do-spaces-syncAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeross DigitalOcean Spaces Sync do-spaces-sync allows Stored XSS.This issue affects DigitalOcean Spaces Sync: from n/a through <= 2.2.1. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure File Sync | 12/8/2025 | 17/6/2026 | Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.3) | 0.19% | — | Couchbase Sync Gateway | 29/7/2025 | 17/6/2026 | An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output. | |
| Analizada | Media (4.8) | 0.11% | — | Dell Appsync | 21/7/2025 | 17/6/2026 | Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| Analizada | Media (6.6) | 0.40% | — | Dell Appsync | 21/7/2025 | 17/6/2026 | Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Alta (7.5) | 4.5% | ⚠ Explotación activa💥 PoC | Eslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+3 | 19/7/2025 | 17/6/2026 | eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. | |
| Aplazada | Media (5.2) | 0.18% | — | Datasync CenterAI | 9/7/2025 | 17/6/2026 | A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Center: from 1.1.0 before 1.1.0.r207, and from 1.2.0 before 1.2.0.r206. | |
| Aplazada | Alta (8.7) | 0.43% | — | EspasynchttpserverAI | 27/6/2025 | 17/6/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows… | |
| Analizada | Alta (7.3) | 0.32% | — | 2brightsparks Syncbackfree | 6/6/2025 | 17/6/2026 | 2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 2BrightSparks SyncBackFree. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Analizada | Alta (8.7) | 0.47% | — | Qnap Qsync Central | 6/6/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later | |
| Analizada | Baja (2.3) | 0.36% | — | Qnap Qsync Central | 6/6/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6… | |
| Analizada | Media (5.3) | 0.33% | — | Syntacticsinc Easync | 31/5/2025 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for… |