Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.63% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714. | |
| Aplazada | Alta (7.5) | 0.52% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734. | |
| Aplazada | Media (4.3) | 0.49% | — | Solidwp Ithemes SyncAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SolidWP iThemes Sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through 2.1.13. | |
| Aplazada | Media (4.3) | 0.53% | — | Wptrio Stock Sync FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2. | |
| Analizada | Media (6.8) | 1.4% | 💥 PoC | Qnap Qsync Central | 6/12/2024 | 17/6/2026 | A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 (… | |
| Analizada | Crítica (9.5) | 2.3% | — | Qnap Hybrid Backup Sync | 6/12/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later | |
| Aplazada | Media (6.5) | 0.25% | — | Captivateaudio Captivate SyncAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Stored XSS.This issue affects Captivate Sync: from n/a through <= 2.0.22. | |
| Aplazada | Media (6.1) | 0.39% | — | Splash SyncAI | 6/12/2024 | 17/6/2026 | The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Aplazada | Crítica (9.2) | 0.64% | — | AsynchttpclientAI | 2/12/2024 | 17/6/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined Cookies with any that have the same name… | |
| Analizada | Media (6.5) | 0.53% | — | Cisco Asyncos | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because confidential information is being… | |
| Analizada | Alta (8.8) | 1.9% | — | Cisco Asyncos | 15/11/2024 | 17/6/2026 | A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient… | |
| Aplazada | Alta (7.1) | 0.27% | — | YES WE Work Fabrica Synced Pattern InstancesAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yes We Work Fabrica Synced Pattern Instances fabrica-reusable-block-instances allows Reflected XSS.This issue affects Fabrica Synced Pattern Instances: from n/a through <= 1.0.8. | |
| Analizada | Media (5.4) | 0.28% | — | Cisco Asyncos | 6/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability… | |
| Aplazada | Baja (2.3) | 0.58% | — | Cap-stdAICap-std Cap-primitivesAICap-std Cap-async-stdAI | 5/11/2024 | 17/6/2026 | The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write capability-based code. cap-std's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block… | |
| Aplazada | Alta (8.4) | 0.20% | — | Wear SyncAI | 24/10/2024 | 17/6/2026 | Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |
| Analizada | Media (6.1) | 0.71% | — | Apache Syncope | 24/10/2024 | 17/6/2026 | When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in Syncope Enduser when editing “Personal… | |
| Aplazada | Alta (7.5) | 4.2% | 💥 Exploit | Lawo VSM LTC Time SyncAI | 24/10/2024 | 17/6/2026 | The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the… | |
| Analizada | Media (4.3) | 0.22% | — | Dell EMC Appsync | 9/10/2024 | 17/6/2026 | Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Aplazada | Alta (7.5) | 0.57% | — | Innate Images LLC VR CalendarAIInnate Images LLC VR Calendar SyncAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0. | |
| Aplazada | Alta (7.5) | 0.58% | — | Async-graphqlAI | 3/10/2024 | 17/6/2026 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10. | |
| Modificada | Media (6.1) | 0.22% | — | Otasync OTA Sync Booking Engine Widget | 21/8/2024 | 17/6/2026 | The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This is due to missing or incorrect nonce validation on the otasync_widget_settings_fnc() function. This makes it possible for unauthenticated attackers to update the… | |
| Aplazada | Media (6.4) | 0.34% | — | Sheet TO Table Live Sync FOR Google SheetAI | 14/8/2024 | 17/6/2026 | The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (4.3) | 0.32% | — | Syncpostwithothersite Sync Post With Other Site | 3/8/2024 | 17/6/2026 | The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create… | |
| Modificada | Media (5.4) | 0.71% | — | Apache Syncope | 22/7/2024 | 17/6/2026 | When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which… | |
| Analizada | Alta (7.8) | 0.16% | — | Cisco Asyncos | 17/7/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by… |