Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.1%—Cisco Asyncos4/9/202017/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insufficient validation of requests that are sent to the web-based…
ModificadaCrítica (9.8)2.4%—Magic AsyncpgDebian Linux12/8/202017/6/2026
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
ModificadaMedia (5.8)1.4%—Cisco Asyncos18/6/202017/6/2026
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could…
ModificadaAlta (7.5)1.3%—Couchbase ServerCouchbase Sync Gateway8/6/202017/6/2026
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the Slowloris denial-of-service attack because they don't more aggressively terminate slow connections.
ModificadaAlta (7.8)0.73%—Asus Aura Sync2/6/202017/6/2026
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
ModificadaCrítica (9.8)2.6%—Node-dns-sync Project Node-dns-sync28/5/202017/6/2026
node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.
ModificadaAlta (7.8)8.6%💥 ExploitDruva Insync Client21/5/202017/6/2026
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
ModificadaCrítica (9.8)4.8%—Apache Syncope4/5/202017/6/2026
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.
ModificadaCrítica (9.8)5.0%—Apache Syncope4/5/202017/6/2026
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom…
ModificadaMedia (5.4)1.2%—Apache Syncope4/5/202017/6/2026
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.
ModificadaCrítica (9.8)4.7%💥 ExploitAasync29/4/202017/6/2026
AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
ModificadaAlta (7.8)0.57%—Druva Insync24/3/202017/6/2026
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
ModificadaCrítica (9.8)1.9%—Linbit Csync220/3/202017/6/2026
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
ModificadaAlta (7.5)1.1%—Sync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor16/3/202017/6/2026
Oxygen XML Editor 21.1.1 allows XXE to read any file.
ModificadaAlta (7.5)4.7%💥 ExploitSynchro BBS27/2/202017/6/2026
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.
ModificadaAlta (7.8)0.73%—Druva Insync25/2/202017/6/2026
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
ModificadaAlta (7.8)8.6%💥 ExploitDruva Insync Client25/2/202017/6/2026
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
ModificadaMedia (6.5)1.3%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
ModificadaMedia (6.5)1.2%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.
ModificadaMedia (6.1)0.67%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
ModificadaAlta (7.5)0.91%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
ModificadaAlta (7.5)1.1%—Meinbergglobal Syncbox/ptpv2 Firmware21/1/202017/6/2026
The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The private key is also used in an internal interface of another Meinberg Device and can be extracted from a firmware update of…
Orbitaley — Vulnerabilidades