Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.5%—Samsung Syncthru WEB ServiceSamsung X7400gx Firmware21/3/201917/6/2026
XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters: ruiFw_id, ruiFw_pid, ruiFw_title.
ModificadaMedia (6.1)1.6%—Samsung Syncthru WEB ServiceSamsung X7400gx Firmware21/3/201917/6/2026
XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc.
AnalizadaCrítica (9.8)87%⚠ Explotación activa💥 ExploitConnectwise Manageditsync5/2/201913/8/2026
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the…
ModificadaAlta (8.6)2.5%—Cisco Asyncos10/1/201917/6/2026
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due…
ModificadaMedia (5.5)0.53%—Asus Aura Sync Firmware26/12/201817/6/2026
The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.
ModificadaAlta (7.8)0.57%—Asus Aura Sync Firmware26/12/201817/6/2026
The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
ModificadaAlta (7.8)0.57%—Asus Aura Sync Firmware26/12/201817/6/2026
The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
ModificadaMedia (6.5)0.74%—Blinkforhome Sync Module15/12/201817/6/2026
A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi, because incident clips (triggered by the motion sensor) are not saved if the attacker's traffic (such as Dot11Deauth) successfully disconnects the Sync Module from the Wi-Fi network.…
ModificadaAlta (7.2)2.5%—Apache Syncope6/11/201817/6/2026
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
ModificadaMedia (5.4)1.2%—Apache Syncope6/11/201817/6/2026
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the…
ModificadaCrítica (9.8)2.5%—Axon Evidence Sync26/9/201817/6/2026
Axon (formerly TASER International) Evidence Sync 3.15.89 is vulnerable to process injection. NOTE: the vendor's position is that this CVE is not associated with information that supports any finding of any type of vulnerability
ModificadaAlta (7.5)0.76%—Dell EMC Vplex Geosynchrony11/9/201817/6/2026
Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration files on and potentially author a MITM attack on the VPN traffic.
ModificadaAlta (8.8)0.51%—Samsung Syncthru WEB Service3/8/201817/6/2026
Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action.
ModificadaMedia (6.1)0.69%—Samsung Syncthru WEB Service3/8/201817/6/2026
Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid.
ModificadaCrítica (9.8)5.1%—Dns-sync Project Dns-sync7/6/201817/6/2026
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
ModificadaMedia (6.5)2.6%—Sync-exec Project Sync-execNodejs Node.js4/6/201817/6/2026
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the…
ModificadaAlta (8.1)1.7%—Httpsync Project Httpsync1/6/201817/6/2026
httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between…
ModificadaMedia (6.1)0.69%—Flexense Syncbreeze2/5/201817/6/2026
An XSS in Flexense SyncBreeze affects all versions (tested from SyncBreeze Enterprise from v10.1 to v10.7).
ModificadaAlta (7.5)3.1%—CorosyncDebian LinuxRedhat Enterprise Linux ServerCanonical Ubuntu Linux12/4/201817/6/2026
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
ModificadaMedia (4.9)20%💥 ExploitApache Syncope20/3/201817/6/2026
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
ModificadaAlta (7.2)18%💥 ExploitApache Syncope20/3/201817/6/2026
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code…
ModificadaAlta (7.8)1.9%💥 ExploitCloudme Sync15/3/201817/6/2026
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" client application listening on 127.0.0.1 port 8888 can send a malicious payload causing a buffer overflow condition. This will result in code execution, as demonstrated by a TCP reverse shell, or a…
ModificadaCrítica (9.8)1.7%—Asyncssh Project Asyncssh12/3/201817/6/2026
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
ModificadaAlta (7.5)76%💥 ExploitFlexense Syncbreeze12/3/201817/6/2026
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be triggered by rapidly sending a variety of HTTP requests with long HTTP header values or long URIs.
ModificadaMedia (5.6)1.8%—Cisco Asyncos8/3/201817/6/2026
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability is due to incorrect FTP user credential validation. An…
Orbitaley — Vulnerabilidades