Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.74% | — | Asyncfuncai Deepwiki-openAI | 11/8/2026 | 28/8/2026 | A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path parameter and returns a directory listing… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Use-reducer-asyncAI | 10/8/2026 | 8/9/2026 | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21e88cafabfb that executed remote attacker-controlled code on developer machines… | |
| Aplazada | Crítica (9.8) | 0.79% | — | Asyncfuncai Deepwiki-openAI | 10/8/2026 | 28/8/2026 | An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner, repo, and repo_type fields without… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Nasa Ammos Asynchronous Network Management SystemAI | 5/8/2026 | 26/8/2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access… | |
| Analizada | Alta (8.2) | 0.59% | — | Asyncssh Project Asyncssh | 17/7/2026 | 30/7/2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, AsyncSSH expands the OpenSSH-compatible AuthorizedKeysFile %u token in asyncssh/config.py, asyncssh/connection.py, asyncssh/auth_keys.py, and… | |
| Aplazada | Alta (8.1) | 0.49% | — | AsyncsshAI | 8/7/2026 | 10/7/2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ traversal sequences… | |
| Aplazada | Media (5.9) | 0.39% | — | AsyncsshAI | 8/7/2026 | 10/7/2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but… | |
| Pendiente de análisis | Media (4) | 0.33% | — | AsynchttpclientAI | 1/7/2026 | 6/8/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the… | |
| Analizada | Alta (7.4) | 0.46% | — | Asynchttpclient Project Async-http-client | 5/6/2026 | 23/7/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin,… | |
| Pendiente de análisis | Alta (8.8) | 0.60% | — | Python AsyncioAI | 21/4/2026 | 13/8/2026 | The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected. | |
| Aplazada | Media (6.8) | 0.48% | — | AsynchttpclientAI | 18/4/2026 | 17/6/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of AsyncHttpClient prior to 3.0.9 and 2.14.5 forward Authorization and Proxy-Authorization headers along with Realm… | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 15/4/2026 | 17/6/2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An… | |
| Aplazada | Alta (7.1) | 0.18% | — | Parisholley Asynchronous JavascriptAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paris Holley Asynchronous Javascript asynchronous-javascript allows Reflected XSS.This issue affects Asynchronous Javascript: from n/a through <= 1.3.5. | |
| Aplazada | Media (4) | 0.16% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 4/2/2026 | 17/6/2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. | |
| Analizada | Crítica (10) | 32% | ⚠ Explotación activa💥 PoC | Cisco Asyncos | 17/12/2025 | 17/6/2026 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient… | |
| Analizada | Crítica (9.8) | 0.43% | — | Long2ice Asyncmy | 2/12/2025 | 17/6/2026 | SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys. | |
| Analizada | Media (5.5) | 0.22% | — | Redboltz Async Mqtt | 24/11/2025 | 17/6/2026 | Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects. | |
| Aplazada | Media (6.4) | 0.26% | — | Async JavascriptAI | 18/10/2025 | 17/6/2026 | The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization checks on the aj_steps AJAX aciton along with a lack on sanitization on the settings saved via the function. This makes it possible for authenticated… | |
| Aplazada | Media (5.2) | 0.18% | — | Datasync CenterAI | 9/7/2025 | 17/6/2026 | A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Center: from 1.1.0 before 1.1.0.r207, and from 1.2.0 before 1.2.0.r206. | |
| Aplazada | Alta (8.7) | 0.43% | — | EspasynchttpserverAI | 27/6/2025 | 17/6/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows… | |
| Analizada | Media (5.3) | 0.33% | — | Syntacticsinc Easync | 31/5/2025 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for… | |
| Analizada | Media (6.5) | 0.19% | — | Syntacticsinc Easync | 15/5/2025 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack | |
| Aplazada | Media (5.4) | 0.49% | — | Syntacticsinc EasyncAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Syntactics, Inc. eaSYNC easync-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eaSYNC: from n/a through <= 1.3.19. | |
| Analizada | Media (5.3) | 0.39% | — | Cisco Asyncos | 4/3/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information. | |
| Analizada | Media (6.7) | 0.19% | — | Cisco Asyncos | 5/2/2025 | 17/6/2026 | A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid… |