Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

685 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.32%—Syncpostwithothersite Sync Post With Other Site3/8/202417/6/2026
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create…
ModificadaMedia (5.4)0.71%—Apache Syncope22/7/202417/6/2026
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which…
AnalizadaAlta (7.8)0.16%—Cisco Asyncos17/7/202417/6/2026
A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by…
AnalizadaAlta (7.2)0.62%—Cisco Asyncos17/7/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validation in certain portions of the web-based management interface.…
AplazadaAlta (7.5)0.82%—AsyncAI1/7/202417/6/2026
Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular expressions are not used with untrusted input.
AplazadaMedia (6.5)0.26%—Zksync ERAAI28/6/202417/6/2026
ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to access the stack not properly being converted to cells. This issue has been patched in version 1.5.0.
ModificadaMedia (4.4)0.74%—Microsoft Azure File Sync11/6/202420/7/2026
Microsoft Azure File Sync Elevation of Privilege Vulnerability
AplazadaMedia (5.3)0.40%—Zksync ERAAI27/5/202417/6/2026
ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); check_if_a_executed_last()` in Yul that exposes a bug in evaluation order of Yul function arguments. This vulnerability has been fixed in version 1.3.10. As a…
AnalizadaMedia (6.1)0.39%—Cisco Asyncos15/5/202417/6/2026
A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based…
ModificadaAlta (8.4)0.35%—Cisco Asyncos15/5/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit…
AnalizadaMedia (6.1)0.32%—Cisco Asyncos15/5/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input.…
AnalizadaMedia (4.8)0.29%—Cisco Asyncos15/5/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.29%—Cisco AsyncosCisco Secure Email AND WEB Manager Virtual Appliance M100vCisco Secure Email AND WEB Manager Virtual Appliance M300vCisco Secure Email AND WEB Manager Virtual Appliance M600v15/5/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An…
AplazadaMedia (5.9)0.47%—Zksync ERA Compiler SolidityAI14/5/202417/6/2026
era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DAGCombine` phase while visiting the XOR operation. The issue arises when attempting to fold the expression `!(x cc y)` into `(x !cc y)`. To perform this transformation, the second operand of XOR should…
AplazadaMedia (5.9)0.36%—Wppool Sheets TO WP Table Live SyncAI6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0.
AplazadaAlta (7.8)0.17%—SugarsyncAI3/5/202417/6/2026
Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.
AplazadaMedia (5.4)0.21%—Wpsynchro WP SynchroAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DAEV.Tech WP Migration Plugin DB & Files – WP Synchro.This issue affects WP Migration Plugin DB & Files – WP Synchro: from n/a through 1.11.2.
ModificadaMedia (6.1)0.20%—Syncpostwithothersite Sync Post With Other Site15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site allows Cross Site Request Forgery.This issue affects Sync Post With Other Site: from n/a through <= 1.9.1.
AplazadaAlta (8.6)2.9%💥 ExploitCdata SyncAIEclipse JettyAI5/4/202417/6/2026
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
ModificadaCrítica (9.8)1.5%—Home-made Fastmag Sync25/3/20249/7/2026
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.
AplazadaAlta (8.8)1.2%—Bosch Network SynchronizerAI25/3/202417/6/2026
Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.
ModificadaMedia (6.1)0.37%—Wpexperts WC Shop Sync17/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpexpertsio WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management allows Reflected XSS.This issue affects WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management: from n/a…
ModificadaMedia (5.3)0.50%—Microsoft Azure File Sync13/2/202410/8/2026
Microsoft Azure File Sync Elevation of Privilege Vulnerability
ModificadaMedia (6.8)0.52%—Dell EMC Appsync8/2/202417/6/2026
Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker…
ModificadaAlta (8.1)1.0%💥 PoCQnap Qsync Central2/2/202417/6/2026
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 (…
Orbitaley — Vulnerabilidades