Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Cloudme Sync | 11/2/2018 | 17/6/2026 | An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing… | |
| Modificada | Alta (8.8) | 5.1% | — | Flexense Syncbreeze | 6/2/2018 | 17/6/2026 | A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggered by an authenticated attacker who submits more than 5000 characters as the command name. It will cause termination of the SyncBreeze Enterprise server and possibly… | |
| Modificada | Crítica (9.8) | 4.2% | 💥 PoC | Flexense Syncbreeze | 2/2/2018 | 17/6/2026 | A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9121. | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Flexense DupscoutFlexense DisksavvyFlexense SyncbreezeFlexense Diskpulse | 24/1/2018 | 17/6/2026 | A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the… | |
| Modificada | Alta (7.8) | 0.40% | — | Cisco Asyncos | 18/1/2018 | 17/6/2026 | A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a… | |
| Modificada | Alta (7.5) | 6.4% | 💥 PoC | Samba RsyncDebian LinuxCanonical Ubuntu Linux | 17/1/2018 | 17/6/2026 | The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism. | |
| Modificada | Alta (7.5) | 9.1% | 💥 Exploit | Flexense Syncbreeze | 10/1/2018 | 17/6/2026 | In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121. | |
| Modificada | Alta (7.5) | 1.5% | — | Syncthing | 2/1/2018 | 17/6/2026 | Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Flexense Syncbreeze | 19/12/2017 | 17/6/2026 | The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header on making a connection, resulting in a classic Buffer Overflow that causes a Denial of Service. | |
| Modificada | Alta (7.8) | 2.2% | — | Qnap Qsync | 11/12/2017 | 17/6/2026 | A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines. | |
| Modificada | Crítica (9.8) | 3.3% | — | Samba RsyncDebian Linux | 6/12/2017 | 17/6/2026 | The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the… | |
| Modificada | Baja (3.7) | 1.8% | — | Debian LinuxSamba Rsync | 6/12/2017 | 17/6/2026 | The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions. | |
| Modificada | Alta (7.8) | 12% | 💥 PoC | Flexense Syncbreeze | 3/12/2017 | 17/6/2026 | There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM… | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Asyncos | 30/11/2017 | 17/6/2026 | A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to improper error handling of a malformed MIME header… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Asyncos | 16/11/2017 | 17/6/2026 | A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability… | |
| Modificada | Crítica (9.8) | 5.8% | — | Samba RsyncCanonical Ubuntu LinuxDebian Linux | 6/11/2017 | 17/6/2026 | The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to… | |
| Modificada | Alta (7.8) | 0.32% | — | EMC Appsync | 1/11/2017 | 17/6/2026 | EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Alta (7.8) | 5.5% | 💥 Exploit | Flexense Syncbreeze | 31/10/2017 | 17/6/2026 | Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode. | |
| Modificada | Crítica (9.8) | 1.0% | — | Samba Rsync | 29/10/2017 | 17/6/2026 | rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects. | |
| Modificada | Crítica (9.1) | 3.0% | — | Debian Ftpsync | 17/10/2017 | 17/6/2026 | Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror. | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Flexense Syncbreeze | 10/10/2017 | 17/6/2026 | Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login. | |
| Modificada | Alta (7.5) | 1.4% | — | EMC Appsync | 3/10/2017 | 17/6/2026 | EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Asyncos | 21/9/2017 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the… | |
| Modificada | Crítica (9.8) | 1.5% | — | EMC Appsync | 12/9/2017 | 17/6/2026 | EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Asyncos | 7/9/2017 | 17/6/2026 | A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated, remote attacker to cause an email attachment containing malware to be delivered to the end user. The vulnerability is due… |