Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
685 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.32% | — | Syncpostwithothersite Sync Post With Other Site | 3/8/2024 | 17/6/2026 | The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create… | |
| Modificada | Media (5.4) | 0.71% | — | Apache Syncope | 22/7/2024 | 17/6/2026 | When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which… | |
| Analizada | Alta (7.8) | 0.16% | — | Cisco Asyncos | 17/7/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.2) | 0.62% | — | Cisco Asyncos | 17/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validation in certain portions of the web-based management interface.… | |
| Aplazada | Alta (7.5) | 0.82% | — | AsyncAI | 1/7/2024 | 17/6/2026 | Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular expressions are not used with untrusted input. | |
| Aplazada | Media (6.5) | 0.26% | — | Zksync ERAAI | 28/6/2024 | 17/6/2026 | ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to access the stack not properly being converted to cells. This issue has been patched in version 1.5.0. | |
| Modificada | Media (4.4) | 0.74% | — | Microsoft Azure File Sync | 11/6/2024 | 20/7/2026 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | |
| Aplazada | Media (5.3) | 0.40% | — | Zksync ERAAI | 27/5/2024 | 17/6/2026 | ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); check_if_a_executed_last()` in Yul that exposes a bug in evaluation order of Yul function arguments. This vulnerability has been fixed in version 1.3.10. As a… | |
| Analizada | Media (6.1) | 0.39% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based… | |
| Modificada | Alta (8.4) | 0.35% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input.… | |
| Analizada | Media (4.8) | 0.29% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.29% | — | Cisco AsyncosCisco Secure Email AND WEB Manager Virtual Appliance M100vCisco Secure Email AND WEB Manager Virtual Appliance M300vCisco Secure Email AND WEB Manager Virtual Appliance M600v | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An… | |
| Aplazada | Media (5.9) | 0.47% | — | Zksync ERA Compiler SolidityAI | 14/5/2024 | 17/6/2026 | era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DAGCombine` phase while visiting the XOR operation. The issue arises when attempting to fold the expression `!(x cc y)` into `(x !cc y)`. To perform this transformation, the second operand of XOR should… | |
| Aplazada | Media (5.9) | 0.36% | — | Wppool Sheets TO WP Table Live SyncAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0. | |
| Aplazada | Alta (7.8) | 0.17% | — | SugarsyncAI | 3/5/2024 | 17/6/2026 | Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation. | |
| Aplazada | Media (5.4) | 0.21% | — | Wpsynchro WP SynchroAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DAEV.Tech WP Migration Plugin DB & Files – WP Synchro.This issue affects WP Migration Plugin DB & Files – WP Synchro: from n/a through 1.11.2. | |
| Modificada | Media (6.1) | 0.20% | — | Syncpostwithothersite Sync Post With Other Site | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site allows Cross Site Request Forgery.This issue affects Sync Post With Other Site: from n/a through <= 1.9.1. | |
| Aplazada | Alta (8.6) | 2.9% | 💥 Exploit | Cdata SyncAIEclipse JettyAI | 5/4/2024 | 17/6/2026 | A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions. | |
| Modificada | Crítica (9.8) | 1.5% | — | Home-made Fastmag Sync | 25/3/2024 | 9/7/2026 | An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component. | |
| Aplazada | Alta (8.8) | 1.2% | — | Bosch Network SynchronizerAI | 25/3/2024 | 17/6/2026 | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device. | |
| Modificada | Media (6.1) | 0.37% | — | Wpexperts WC Shop Sync | 17/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpexpertsio WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management allows Reflected XSS.This issue affects WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management: from n/a… | |
| Modificada | Media (5.3) | 0.50% | — | Microsoft Azure File Sync | 13/2/2024 | 10/8/2026 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | |
| Modificada | Media (6.8) | 0.52% | — | Dell EMC Appsync | 8/2/2024 | 17/6/2026 | Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker… | |
| Modificada | Alta (8.1) | 1.0% | 💥 PoC | Qnap Qsync Central | 2/2/2024 | 17/6/2026 | An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 (… |