Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Wptrio Stock Sync FOR Woocommerce18/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions.
ModificadaMedia (4.3)0.74%—Froger WP Remote Users Sync16/8/202317/6/2026
The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to…
ModificadaMedia (5.4)0.73%—Froger WP Remote Users Sync16/8/202317/6/2026
The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from…
ModificadaAlta (7.5)0.89%💥 PoCEminfedar Async-sockets-cpp14/8/202317/6/2026
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.
ModificadaMedia (6.1)0.38%—Syntacticsinc Easync8/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions.
ModificadaMedia (5.3)0.63%—Cisco Asyncos4/8/202317/6/2026
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An…
ModificadaMedia (5.3)0.62%—Cisco Asyncos3/8/202317/6/2026
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper detection of malicious traffic when the…
ModificadaCrítica (9.8)1.9%💥 PoCAsynchronous Sockets FOR C++ Project Asynchronous Sockets FOR C++21/7/202317/6/2026
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.
ModificadaCrítica (9.8)1.7%—Syncfusion EJ2 Aspcore File Provider12/7/202317/6/2026
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.
ModificadaCrítica (9.8)1.9%—Syncfusion Nodejs File System Provider12/7/202317/6/2026
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file,…
ModificadaAlta (7.5)1.3%—Synck Mailform PRO CGI29/6/202317/6/2026
Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
ModificadaMedia (5.5)0.31%—Intellectualsites Fastasyncworldedit23/6/202317/6/2026
FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the performing server down. This issue has been fixed in version 2.6.3.
ModificadaMedia (6.1)0.22%—SAP Master Data Synchronization13/6/202317/6/2026
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.
ModificadaMedia (5.4)0.78%—Syncthing6/6/202317/6/2026
Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance with shared folders could sync malicious files which contain arbitrary HTML and JavaScript in the name. If the owner of another device looks over the shared folder settings and moves the mouse over…
ModificadaAlta (7.5)0.63%—Deviniti Issue Sync31/5/20239/7/2026
An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.
ModificadaMedia (6.5)0.63%—Imapsync Project Imapsync30/5/202317/6/2026
imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, and thus (for example) an attacker can modify imapsync's cache and overwrite files belonging to the user who runs it.
ModificadaAlta (7.8)0.24%—Allwaysync22/5/202317/6/2026
Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate privileges via the SyncService.exe file.
ModificadaAlta (7.5)0.44%—IBM Qradar Data Synchronization6/5/202317/6/2026
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370.
ModificadaMedia (5.3)1.0%—Sync Oxygen Content FusionSync Oxygen XML WEB Author14/4/202317/6/2026
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also…
ModificadaMedia (5.4)0.59%—Pega Synchronization Engine10/4/202317/6/2026
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
ModificadaMedia (6.5)1.4%—Pega Synchronization Engine10/4/202317/6/2026
A user with a compromised configuration can start an unsigned binary as a service.
ModificadaAlta (7.8)0.17%—Pega Synchronization Engine10/4/202317/6/2026
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
ModificadaAlta (8.8)0.26%—Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.
ModificadaMedia (5.3)0.68%—Cisco Asyncos1/3/202317/6/2026
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability…
ModificadaCrítica (9.8)92%💥 ExploitMicrochip Syncserver S650 Firmware13/2/202317/6/2026
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Orbitaley — Vulnerabilidades