Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

682 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.63%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.
AplazadaAlta (7.5)0.52%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.
AplazadaMedia (4.3)0.49%—Solidwp Ithemes SyncAI13/12/202417/6/2026
Missing Authorization vulnerability in SolidWP iThemes Sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through 2.1.13.
AplazadaMedia (4.3)0.53%—Wptrio Stock Sync FOR WoocommerceAI13/12/202417/6/2026
Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.
AnalizadaMedia (6.8)1.4%💥 PoCQnap Qsync Central6/12/202417/6/2026
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 (…
AnalizadaCrítica (9.5)2.3%—Qnap Hybrid Backup Sync6/12/202417/6/2026
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later
AplazadaMedia (6.5)0.25%—Captivateaudio Captivate SyncAI6/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Stored XSS.This issue affects Captivate Sync: from n/a through <= 2.0.22.
AplazadaMedia (6.1)0.39%—Splash SyncAI6/12/202417/6/2026
The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they…
AplazadaCrítica (9.2)0.64%—AsynchttpclientAI2/12/202417/6/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined Cookies with any that have the same name…
AnalizadaMedia (6.5)0.53%—Cisco Asyncos18/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco&nbsp;AsyncOS Software for Cisco&nbsp;Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because confidential information is being…
AnalizadaAlta (8.8)1.9%—Cisco Asyncos15/11/202417/6/2026
A vulnerability in the web management interface of Cisco&nbsp;AsyncOS for Cisco&nbsp;Secure Web Appliance, formerly Cisco&nbsp;Web Security Appliance (WSA),&nbsp;could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient…
AplazadaAlta (7.1)0.27%—YES WE Work Fabrica Synced Pattern InstancesAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yes We Work Fabrica Synced Pattern Instances fabrica-reusable-block-instances allows Reflected XSS.This issue affects Fabrica Synced Pattern Instances: from n/a through <= 1.0.8.
AnalizadaMedia (5.4)0.28%—Cisco Asyncos6/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability…
AplazadaBaja (2.3)0.58%—Cap-stdAICap-std Cap-primitivesAICap-std Cap-async-stdAI5/11/202417/6/2026
The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write capability-based code. cap-std's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block…
AplazadaAlta (8.4)0.20%—Wear SyncAI24/10/202417/6/2026
Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
AnalizadaMedia (6.1)0.71%—Apache Syncope24/10/202417/6/2026
When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in Syncope Enduser when editing “Personal…
AplazadaAlta (7.5)4.2%💥 ExploitLawo VSM LTC Time SyncAI24/10/202417/6/2026
The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the…
AnalizadaMedia (4.3)0.22%—Dell EMC Appsync9/10/202417/6/2026
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
AplazadaAlta (7.5)0.57%—Innate Images LLC VR CalendarAIInnate Images LLC VR Calendar SyncAI5/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0.
AplazadaAlta (7.5)0.58%—Async-graphqlAI3/10/202417/6/2026
async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10.
ModificadaMedia (6.1)0.22%—Otasync OTA Sync Booking Engine Widget21/8/202417/6/2026
The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This is due to missing or incorrect nonce validation on the otasync_widget_settings_fnc() function. This makes it possible for unauthenticated attackers to update the…
AplazadaMedia (6.4)0.34%—Sheet TO Table Live Sync FOR Google SheetAI14/8/202417/6/2026
The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (4.3)0.32%—Syncpostwithothersite Sync Post With Other Site3/8/202417/6/2026
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create…
ModificadaMedia (5.4)0.71%—Apache Syncope22/7/202417/6/2026
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which…
AnalizadaAlta (7.8)0.16%—Cisco Asyncos17/7/202417/6/2026
A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by…
Orbitaley — Vulnerabilidades