Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.8% | — | Amazon Blink XT2 Sync Module Firmware | 31/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. | |
| Modificada | Media (5.9) | 0.65% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted. | |
| Modificada | Crítica (9.8) | 3.3% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution. | |
| Modificada | Crítica (9.8) | 2.4% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp allows Insecure File Upload. | |
| Modificada | Media (6.1) | 1.3% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp has XSS. | |
| Modificada | Alta (8.8) | 0.86% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp has CSRF. | |
| Modificada | Crítica (9.8) | 2.0% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp has SQL Injection. | |
| Modificada | Crítica (9.8) | 2.3% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 2.7% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246. | |
| Modificada | Media (4.3) | 1.4% | — | Intesync Solismed | 12/12/2019 | 17/6/2026 | Intesync Solismed 3.3sp allows Clickjacking. | |
| Modificada | Crítica (9.8) | 3.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter. | |
| Modificada | Media (6.8) | 1.0% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections. | |
| Modificada | Alta (8.8) | 0.98% | — | Cisco AsyncosCisco WEB Security Appliance | 26/11/2019 | 17/6/2026 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web… | |
| Modificada | Alta (8.8) | 1.3% | 💥 Exploit | Synametrics SynamanSynametrics SyncrifySynametrics Syntail | 21/11/2019 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567 | |
| Modificada | Alta (7.5) | 1.7% | — | WP Slacksync | 12/11/2019 | 17/6/2026 | WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in… | |
| Modificada | Crítica (9.8) | 2.7% | — | Couchbase Sync Gateway | 26/6/2019 | 17/6/2026 | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with… | |
| Modificada | Crítica (9.8) | 1.9% | — | Kalkitech Sync3000 Firmware | 22/5/2019 | 17/6/2026 | Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires… | |
| Modificada | Media (6.1) | 1.5% | — | Samsung Syncthru WEB ServiceSamsung X7400gx Firmware | 21/3/2019 | 17/6/2026 | XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.login/gnb/loginView.sws" in multiple parameters: contextpath and basedURL. | |
| Modificada | Media (6.1) | 1.5% | — | Samsung Syncthru WEB ServiceSamsung X7400gx Firmware | 21/3/2019 | 17/6/2026 | XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.application/information/networkinformationView.sws" in the tabName parameter. |