Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.68%—Cisco Asyncos20/1/202317/6/2026
A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this…
ModificadaAlta (7.5)0.55%—Asynchttpclient Project Async-http-client18/1/202317/6/2026
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header…
ModificadaCrítica (9.8)0.88%—Larasync Project Larasync7/1/202317/6/2026
A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file repository/content/file_storage.go. The manipulation leads to path traversal. The name of the patch is 776bad422f4bd4930d09491711246bbeb1be9ba5. It is recommended to apply a patch to fix this issue.…
ModificadaBaja (3.3)0.37%—Cloudsync Project Cloudsync28/12/202217/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnector.java. The manipulation leads to path traversal. It is possible to launch the attack on the…
ModificadaAlta (7.8)0.38%—Asus Aura Sync14/12/202217/6/2026
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
ModificadaAlta (7.5)0.89%—Syncee - Global Dropshipping5/12/202217/6/2026
The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account.
ModificadaMedia (6.5)0.95%—Cisco Asyncos4/11/202217/6/2026
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected…
ModificadaAlta (8.8)0.74%—Cisco Asyncos4/11/202217/6/2026
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This…
ModificadaMedia (6.5)0.80%—Cisco Asyncos4/11/202217/6/2026
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This…
ModificadaCrítica (9.8)4.9%—Syncovery16/9/20229/7/2026
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
ModificadaAlta (8.8)52%💥 ExploitSyncovery16/9/20229/7/2026
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
ModificadaMedia (5.4)43%—Syncovery16/9/20229/7/2026
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.
ModificadaMedia (5.9)1.5%—Synck Mailform PRO CGI8/9/202217/6/2026
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL.
ModificadaAlta (7.5)1.3%—Asyncua Project AsyncuaOpcua Project Opcua23/8/202217/6/2026
All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks…
ModificadaAlta (7.4)2.3%💥 PoCSamba RsyncFedoraproject Fedora2/8/202217/6/2026
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server…
ModificadaMedia (6.1)0.47%—Sync Oxygen Publishing EngineSync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor+113/7/202217/6/2026
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp…
ModificadaAlta (7.8)0.58%—Druva Insync Client12/7/20229/7/2026
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
ModificadaAlta (7.8)2.7%—Druva Insync Client12/7/20229/7/2026
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
ModificadaAlta (7.8)0.46%—Druva Insync Client12/7/20229/7/2026
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
ModificadaAlta (7.8)0.51%—Druva Insync Client12/7/20229/7/2026
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
ModificadaCrítica (9.8)25%💥 ExploitSyntacticsinc Easync11/7/202217/6/2026
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid…
ModificadaCrítica (9.3)1.3%—Ytdl-sync Project Ytdl-sync11/7/202217/6/2026
The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.8)0.81%—Couchbase Sync Gateway10/6/202217/6/2026
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials…
ModificadaMedia (4.3)0.43%—Livesync Project Livesync8/6/202217/6/2026
The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.5)1.1%—IBM Security Verify Password Synchronization27/4/202217/6/2026
IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID:…
Orbitaley — Vulnerabilidades