Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.39% | — | Synck Mailform PRO CGI | 26/5/2025 | 17/6/2026 | Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature. | |
| Analizada | Crítica (9.8) | 0.34% | — | Forestryks Process-sync | 24/5/2025 | 17/6/2026 | In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked. | |
| Analizada | Baja (3.1) | 0.22% | — | Single Content Sync Project Single Content Sync | 21/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12. | |
| Analizada | Media (6.5) | 0.19% | — | Syntacticsinc Easync | 15/5/2025 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack | |
| Analizada | Alta (7) | 0.30% | — | Microsoft Azure File Sync | 13/5/2025 | 17/6/2026 | Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.45% | — | Dbsyncer Project Dbsyncer | 5/5/2025 | 17/6/2026 | Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password. | |
| Modificada | Media (5.4) | 0.27% | — | Dbsyncer Project Dbsyncer | 5/5/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter. | |
| Analizada | Media (4.3) | 0.32% | — | Aeropage Sync FOR Airtable | 26/4/2025 | 17/6/2026 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Analizada | Alta (8.8) | 17% | 💥 PoC | Aeropage Sync FOR Airtable | 26/4/2025 | 17/6/2026 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Aplazada | Alta (7.1) | 0.15% | — | Kiotviet SyncAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kiotviet KiotViet Sync allows Stored XSS. This issue affects KiotViet Sync: from n/a through 1.8.4. | |
| Aplazada | Alta (8.5) | 0.43% | — | Kiotviet SyncAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. This issue affects KiotViet Sync: from n/a through 1.8.3. | |
| Aplazada | Crítica (9.9) | 0.73% | 💥 PoC | Softclever Limited Sync PostsAI | 11/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.42% | — | Myworks WOO Sync FOR Quickbooks OnlineAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online myworks-woo-sync-for-quickbooks-online allows Reflected XSS.This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a through <= 2.9.1. | |
| Aplazada | Crítica (9.3) | 0.65% | — | Nmedia Bulk Product SyncAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows SQL Injection.This issue affects Bulk Product Sync: from n/a through <= 8.6. | |
| Aplazada | Alta (7.1) | 0.19% | — | Rafasashi User Session SynchronizerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer user-session-synchronizer allows Stored XSS.This issue affects User Session Synchronizer: from n/a through <= 1.4.0. | |
| Aplazada | Media (5.4) | 0.49% | — | Syntacticsinc EasyncAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Syntactics, Inc. eaSYNC easync-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eaSYNC: from n/a through <= 1.3.19. | |
| Aplazada | Alta (8.5) | 0.46% | — | Marcoingraiti Actionwear-products-syncAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows SQL Injection.This issue affects Actionwear products sync: from n/a through <= 2.3.3. | |
| Aplazada | Media (4.3) | 0.17% | — | Nmedia Bulk Product SyncAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in N-Media Bulk Product Sync sync-wc-google allows Cross Site Request Forgery.This issue affects Bulk Product Sync: from n/a through <= 8.6. | |
| Aplazada | Media (5.3) | 0.37% | — | DAP TO Autoresponders Email SyncingAI | 29/3/2025 | 17/6/2026 | The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the… | |
| Modificada | Crítica (9.8) | 0.46% | — | Corosync | 22/3/2025 | 17/6/2026 | Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet. | |
| Analizada | Crítica (10) | 1.4% | — | Synology Unified ControllerSynology Replication ServiceSyncology Replication Service | 19/3/2025 | 17/6/2026 | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via… | |
| Aplazada | Alta (7.1) | 0.15% | — | A2rocklobster FTP SyncAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <= 1.1.6. | |
| Analizada | Media (6.3) | 0.52% | — | Qnap Hybrid Backup Sync | 7/3/2025 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later | |
| Aplazada | Alta (8.6) | 0.13% | — | Qnap Qvpn Device ClientAIQnap QsyncAIQnap Qfinder PROAI | 7/3/2025 | 17/6/2026 | A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.3) | 0.39% | — | Cisco Asyncos | 4/3/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information. |