Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.1%—Cisco Asyncos6/10/202117/6/2026
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this…
ModificadaAlta (7.8)0.88%—Asyncapi Java-spring-cloud-stream-template11/8/202117/6/2026
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised…
ModificadaAlta (8.1)1.2%—Syncpool Project Syncpool8/8/202117/6/2026
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.
ModificadaAlta (8.1)0.77%—Async-coap Project Async-coap8/8/202117/6/2026
An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<RC, T> without trait bounds on RC.
ModificadaAlta (8.8)1.9%—Cisco WEB Security ApplianceCisco Asyncos8/7/202117/6/2026
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An…
ModificadaCrítica (9.8)16%—Qnap Hybrid Backup Sync8/7/202117/6/2026
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and…
ModificadaAlta (7.4)0.67%—Cisco Email Security ApplianceCisco AsyncosCisco WEB Security Appliance16/6/202117/6/2026
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This…
ModificadaAlta (7.4)1.1%—Samba Rsync27/5/202117/6/2026
A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and…
AnalizadaCrítica (9.8)78%⚠ Explotación activa💥 ExploitQnap Hybrid Backup Sync13/5/202117/6/2026
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS…
ModificadaAlta (7.5)0.73%—Pgsync Project Pgsync27/4/202117/6/2026
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.
ModificadaAlta (7.5)2.0%—Syncthing6/4/202117/6/2026
Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and exit by sending a relay message with a negative length field. Similarly, Syncthing itself can crash for the same reason if given a malformed message from a malicious…
ModificadaAlta (7.4)1.9%—Mbsync Project MbsyncFedoraproject Extra Packages FOR Enterprise LinuxDebian LinuxFedoraproject Fedora23/2/202117/6/2026
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the…
ModificadaCrítica (9.8)2.5%—Async-git Project Async-git18/2/202117/6/2026
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
ModificadaCrítica (9.8)5.3%—Async-git Project Async-git26/1/202117/6/2026
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
ModificadaMedia (6.1)0.81%—Rust-lang Async-h126/1/202117/6/2026
An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.
ModificadaMedia (5.3)1.3%—Linbit Csync2Debian Linux30/12/202017/6/2026
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
ModificadaAlta (8.8)7.8%—Raysync23/12/202017/6/2026
A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.
ModificadaAlta (7.5)1.0%—Rust-lang Async-h121/12/202017/6/2026
async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async-h1 behind a reverse proxy, including all such Tide applications. If the server does not read the body of a request…
ModificadaAlta (7.8)0.29%—Druva Insync7/12/202017/6/2026
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
ModificadaAlta (7.8)0.80%—Cisco Asyncos18/11/202017/6/2026
A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input…
ModificadaMedia (5.8)1.0%—Cisco Asyncos8/10/202017/6/2026
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could…
ModificadaMedia (5.3)1.9%—Cisco Content Security Management ApplianceCisco AsyncosCisco Email Security Appliance23/9/202017/6/2026
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices,…
ModificadaAlta (8.6)1.9%—Cisco Email Security ApplianceCisco Asyncos23/9/202017/6/2026
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due…
ModificadaAlta (7.2)2.9%—Apache Syncope15/9/202017/6/2026
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.
ModificadaMedia (6.5)0.88%—Cisco Asyncos4/9/202017/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The…
Orbitaley — Vulnerabilidades