Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.17%—SugarsyncAI3/5/202417/6/2026
Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.
AplazadaMedia (5.4)0.21%—Wpsynchro WP SynchroAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DAEV.Tech WP Migration Plugin DB & Files – WP Synchro.This issue affects WP Migration Plugin DB & Files – WP Synchro: from n/a through 1.11.2.
ModificadaMedia (6.1)0.20%—Syncpostwithothersite Sync Post With Other Site15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site allows Cross Site Request Forgery.This issue affects Sync Post With Other Site: from n/a through <= 1.9.1.
AplazadaAlta (8.6)2.9%💥 ExploitCdata SyncAIEclipse JettyAI5/4/202417/6/2026
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
ModificadaCrítica (9.8)1.5%—Home-made Fastmag Sync25/3/20249/7/2026
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.
AplazadaAlta (8.8)1.2%—Bosch Network SynchronizerAI25/3/202417/6/2026
Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.
ModificadaMedia (6.1)0.37%—Wpexperts WC Shop Sync17/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpexpertsio WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management allows Reflected XSS.This issue affects WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management: from n/a…
ModificadaMedia (5.3)0.50%—Microsoft Azure File Sync13/2/202410/8/2026
Microsoft Azure File Sync Elevation of Privilege Vulnerability
ModificadaMedia (6.8)0.52%—Dell EMC Appsync8/2/202417/6/2026
Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker…
ModificadaAlta (8.1)1.0%💥 PoCQnap Qsync Central2/2/202417/6/2026
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 (…
ModificadaAlta (7.8)0.75%—Perforce Helix Sync1/2/202417/6/2026
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
ModificadaCrítica (9.1)0.56%—Magiclogix Msync20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magic Logix MSync.This issue affects MSync: from n/a through 1.0.0.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.8)0.23%—Antonymale Synctrayzor9/12/202317/6/2026
SyncTrayzor 1.1.29 enables CEF (Chromium Embedded Framework) remote debugging, allowing a local attacker to control the application.
ModificadaAlta (8.8)0.30%—Wppool Sheets TO WP Table Live Sync22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.
ModificadaMedia (6.8)0.87%—Asyncssh Project Asyncssh14/11/202317/6/2026
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
ModificadaMedia (5.9)0.59%—Asyncssh Project Asyncssh14/11/202317/6/2026
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
AnalizadaAlta (7.8)0.41%—Relative Synchrony17/10/202317/6/2026
Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties…
ModificadaAlta (8.8)0.31%—Wpsynchro WP Synchro9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPSynchro WP Synchro plugin <= 1.9.1 versions.
ModificadaAlta (7.5)1.2%—Freeopcua Opcua-asyncio3/10/202317/6/2026
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
ModificadaAlta (7.5)0.52%—Freeopcua Opcua-asyncio3/10/202317/6/2026
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.
ModificadaAlta (7.8)0.18%—EMC Appsync27/9/202317/6/2026
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege escalation.
ModificadaMedia (5.4)0.36%—Tencent Wxsync4/9/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 标准云(std.Cloud) WxSync plugin <= 2.7.23 versions.
ModificadaAlta (7.5)0.89%—Synck Graphica Mailform PRO CGI25/8/202317/6/2026
Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-of-service condition. Affected add-ons are as follows: call/call.js, prefcodeadv/search.cgi, estimate/estimate.js, search/search.js,…
ModificadaAlta (7.5)0.52%—Samsung Syncthru WEB Service22/8/202317/6/2026
An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.
Orbitaley — Vulnerabilidades