Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

682 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.39%—Synck Mailform PRO CGI26/5/202517/6/2026
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
AnalizadaCrítica (9.8)0.34%—Forestryks Process-sync24/5/202517/6/2026
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
AnalizadaBaja (3.1)0.22%—Single Content Sync Project Single Content Sync21/5/202517/6/2026
Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.
AnalizadaMedia (6.5)0.19%—Syntacticsinc Easync15/5/202517/6/2026
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
AnalizadaAlta (7)0.30%—Microsoft Azure File Sync13/5/202517/6/2026
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.45%—Dbsyncer Project Dbsyncer5/5/202517/6/2026
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
ModificadaMedia (5.4)0.27%—Dbsyncer Project Dbsyncer5/5/20255/7/2026
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.
AnalizadaMedia (4.3)0.32%—Aeropage Sync FOR Airtable26/4/202517/6/2026
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AnalizadaAlta (8.8)17%💥 PoCAeropage Sync FOR Airtable26/4/202517/6/2026
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload…
AplazadaAlta (7.1)0.15%—Kiotviet SyncAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kiotviet KiotViet Sync allows Stored XSS. This issue affects KiotViet Sync: from n/a through 1.8.4.
AplazadaAlta (8.5)0.43%—Kiotviet SyncAI17/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. This issue affects KiotViet Sync: from n/a through 1.8.3.
AplazadaCrítica (9.9)0.73%💥 PoCSoftclever Limited Sync PostsAI11/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0.
AplazadaAlta (7.1)0.42%—Myworks WOO Sync FOR Quickbooks OnlineAI11/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online myworks-woo-sync-for-quickbooks-online allows Reflected XSS.This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a through <= 2.9.1.
AplazadaCrítica (9.3)0.65%—Nmedia Bulk Product SyncAI11/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows SQL Injection.This issue affects Bulk Product Sync: from n/a through <= 8.6.
AplazadaAlta (7.1)0.19%—Rafasashi User Session SynchronizerAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer user-session-synchronizer allows Stored XSS.This issue affects User Session Synchronizer: from n/a through <= 1.4.0.
AplazadaMedia (5.4)0.49%—Syntacticsinc EasyncAI4/4/202517/6/2026
Missing Authorization vulnerability in Syntactics, Inc. eaSYNC easync-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eaSYNC: from n/a through <= 1.3.19.
AplazadaAlta (8.5)0.46%—Marcoingraiti Actionwear-products-syncAI1/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows SQL Injection.This issue affects Actionwear products sync: from n/a through <= 2.3.3.
AplazadaMedia (4.3)0.17%—Nmedia Bulk Product SyncAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in N-Media Bulk Product Sync sync-wc-google allows Cross Site Request Forgery.This issue affects Bulk Product Sync: from n/a through <= 8.6.
AplazadaMedia (5.3)0.37%—DAP TO Autoresponders Email SyncingAI29/3/202517/6/2026
The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the…
ModificadaCrítica (9.8)0.46%—Corosync22/3/202517/6/2026
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
AnalizadaCrítica (10)1.4%—Synology Unified ControllerSynology Replication ServiceSyncology Replication Service19/3/202517/6/2026
Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via…
AplazadaAlta (7.1)0.15%—A2rocklobster FTP SyncAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <= 1.1.6.
AnalizadaMedia (6.3)0.52%—Qnap Hybrid Backup Sync7/3/202517/6/2026
A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later
AplazadaAlta (8.6)0.13%—Qnap Qvpn Device ClientAIQnap QsyncAIQnap Qfinder PROAI7/3/202517/6/2026
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following…
AnalizadaMedia (5.3)0.39%—Cisco Asyncos4/3/202517/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.
Orbitaley — Vulnerabilidades