Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.1% | — | IBM Security Verify Password Synchronization | 27/4/2022 | 17/6/2026 | IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID:… | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Commoninja Videos Sync PDF | 25/4/2022 | 17/6/2026 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues | |
| Modificada | Alta (7.5) | 1.7% | — | Dell EMC Appsync | 21/4/2022 | 17/6/2026 | Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. | |
| Modificada | Alta (7) | 0.18% | — | Logitech Sync | 12/4/2022 | 17/6/2026 | There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user. | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Asyncos | 6/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the… | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Asyncos | 6/4/2022 | 17/6/2026 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a… | |
| Modificada | Alta (7.8) | 3.3% | — | Async Project AsyncFedoraproject Fedora | 6/4/2022 | 17/6/2026 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. | |
| Modificada | Alta (7.2) | 1.3% | — | DPL Sync Woocommerce Product Feed TO Google Shopping | 28/3/2022 | 17/6/2026 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard | |
| Modificada | Media (4.8) | 0.60% | — | Sync Qcloud COS Project Sync Qcloud COS | 14/3/2022 | 17/6/2026 | The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.1) | 0.80% | — | Obtaininfotech Multisite User Sync/unsync | 7/3/2022 | 17/6/2026 | The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Crítica (9.8) | 3.5% | — | Isync Project IsyncFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 18/2/2022 | 17/6/2026 | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution. | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco Asyncos | 17/2/2022 | 17/6/2026 | A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to… | |
| Modificada | Alta (7.8) | 1.0% | — | Isync Project IsyncFedoraproject FedoraDebian Linux | 16/2/2022 | 17/6/2026 | A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell EMC Appsync | 21/1/2022 | 17/6/2026 | Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak… | |
| Modificada | Media (6.1) | 0.69% | — | Dell EMC Appsync | 21/1/2022 | 17/6/2026 | Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations. | |
| Modificada | Alta (8.8) | 0.39% | — | Dell EMC Appsync | 21/1/2022 | 17/6/2026 | DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session. | |
| Modificada | Alta (8.1) | 0.92% | — | Kalkitech Sync241-m1 FirmwareKalkitech Sync241-m2 FirmwareKalkitech Sync241-m4 FirmwareKalkitech Sync261-m1 Firmware+16 | 6/1/2022 | 17/6/2026 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and… | |
| Modificada | Alta (7.5) | 1.8% | 💥 PoC | Samsung Syncthru WEB Service | 20/12/2021 | 17/6/2026 | The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.1) | 0.52% | — | Couchbase Sync Gateway | 7/12/2021 | 17/6/2026 | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were insecurely being stored in the metadata within sync documents written to the bucket. Users with read access could use these credentials to obtain write access. (This issue… | |
| Modificada | Crítica (9.8) | 3.8% | — | Isync Project IsyncDebian LinuxFedoraproject Fedora | 22/11/2021 | 17/6/2026 | A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Asyncos | 4/11/2021 | 17/6/2026 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An… | |
| Modificada | Alta (7.5) | 1.7% | — | Modern-async Project Modern-async | 20/10/2021 | 17/6/2026 | modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code… | |
| Modificada | Alta (7.5) | 0.95% | — | Synchro Bulletin Board System | 19/10/2021 | 9/7/2026 | An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Asyncos | 6/10/2021 | 17/6/2026 | A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management in the proxy service of an… |