Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.0% | — | Asynchttpclient Project Async-http-client | 31/8/2017 | 17/6/2026 | Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL. | |
| Modificada | Crítica (9.8) | 13% | — | Samsung Syncthru 6 | 1/6/2017 | 17/6/2026 | Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addDriver or to execute arbitrary code with SYSTEM privileges via unspecified parameters to (3) uploadCloning.html, (4)… | |
| Modificada | Alta (7.8) | 54% | 💥 Exploit | Flexense DiskbossFlexense DisksorterFlexense Syncbreeze | 29/3/2017 | 17/6/2026 | A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a… | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Asyncos | 1/8/2016 | 17/6/2026 | Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932. | |
| Modificada | Alta (8.1) | 5.1% | 💥 Exploit | Meinberg NTP Server FirmwareMeinberg Ims-lantime M1000Meinberg Ims-lantime M3000Meinberg Ims-lantime M500+8 | 3/7/2016 | 17/6/2026 | The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote authenticated users to obtain root privileges for writing to… | |
| Modificada | Alta (7.3) | 1.1% | — | Meinberg NTP Server FirmwareMeinberg Ims-lantime M1000Meinberg Ims-lantime M3000Meinberg Ims-lantime M500+8 | 3/7/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allow remote attackers to obtain… | |
| Modificada | Alta (7.3) | 5.2% | 💥 Exploit | Meinberg NTP Server FirmwareMeinberg Ims-lantime M1000Meinberg Ims-lantime M3000Meinberg Ims-lantime M500+8 | 3/7/2016 | 17/6/2026 | Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote attackers to obtain sensitive… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Asyncos | 23/6/2016 | 17/6/2026 | Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210. | |
| Modificada | Alta (8.4) | 0.54% | — | EMC Vplex Geosynchrony | 28/12/2015 | 17/6/2026 | EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privileges by leveraging a login session. | |
| Modificada | Baja (2.1) | 0.51% | — | EMC Vplex Geosynchrony | 18/11/2015 | 17/6/2026 | The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Media (5.8) | 2.9% | — | Librsync Project Librsync | 26/10/2015 | 17/6/2026 | librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack. | |
| Modificada | Alta (8.5) | 2.5% | — | Pacemaker/corosync Configuration System Project Pacemaker/corosync Configuration System | 3/9/2015 | 17/6/2026 | The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL. | |
| Modificada | Media (4.9) | 0.98% | — | Pacemaker/corosync Configuration System Project Pacemaker/corosync Configuration System | 3/9/2015 | 17/6/2026 | Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated. | |
| Modificada | Media (4.3) | 0.83% | — | Async-http-client Project Async-http-clientRedhat Jboss Fuse | 24/6/2015 | 17/6/2026 | main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | |
| Modificada | Media (4.3) | 0.99% | — | Redhat Jboss FuseAsync-http-client Project Async-http-client | 24/6/2015 | 17/6/2026 | Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC… | |
| Modificada | Alta (9.3) | 3.6% | — | Bittorrent Sync | 13/4/2015 | 17/6/2026 | BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link. | |
| Modificada | Alta (10) | 2.8% | — | Dns-sync Project Dns-sync | 28/2/2015 | 17/6/2026 | The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function. | |
| Modificada | Media (6.8) | 2.3% | — | Synck Graphica Mailform PRO CGI | 27/2/2015 | 17/6/2026 | SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.4) | 6.5% | — | Samba RsyncOpensuseOracle Solaris | 12/2/2015 | 17/6/2026 | rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path. | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Asyncos | 7/2/2015 | 17/6/2026 | The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343. | |
| Modificada | Media (5) | 1.9% | — | Synck Graphica Download LOG CGI | 21/1/2015 | 17/6/2026 | Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename. | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Asyncos | 14/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the IronPort Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA), allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs… | |
| Modificada | Media (4.6) | 0.41% | — | EMC AppsyncEMC Replication Manager | 30/12/2014 | 17/6/2026 | Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | |
| Modificada | Alta (7.5) | 5.2% | — | Debian LinuxFedoraproject FedoraLsyncd Project Lsyncd | 5/12/2014 | 17/6/2026 | default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (5.4) | 0.29% | — | Sasync | 19/10/2014 | 17/6/2026 | The SAsync (aka com.sasync.sasyncmap) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |