Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.63% | — | Cisco Asyncos | 4/8/2023 | 17/6/2026 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An… | |
| Modificada | Media (5.3) | 0.62% | — | Cisco Asyncos | 3/8/2023 | 17/6/2026 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper detection of malicious traffic when the… | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Asynchronous Sockets FOR C++ Project Asynchronous Sockets FOR C++ | 21/7/2023 | 17/6/2026 | async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets. | |
| Modificada | Media (5.5) | 0.31% | — | Intellectualsites Fastasyncworldedit | 23/6/2023 | 17/6/2026 | FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the performing server down. This issue has been fixed in version 2.6.3. | |
| Modificada | Alta (8.8) | 0.26% | — | Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | |
| Modificada | Media (5.3) | 0.68% | — | Cisco Asyncos | 1/3/2023 | 17/6/2026 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability… | |
| Modificada | Media (5.3) | 0.68% | — | Cisco Asyncos | 20/1/2023 | 17/6/2026 | A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 0.55% | — | Asynchttpclient Project Async-http-client | 18/1/2023 | 17/6/2026 | Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header… | |
| Modificada | Crítica (9.8) | 0.88% | — | Larasync Project Larasync | 7/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file repository/content/file_storage.go. The manipulation leads to path traversal. The name of the patch is 776bad422f4bd4930d09491711246bbeb1be9ba5. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Media (6.5) | 0.95% | — | Cisco Asyncos | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected… | |
| Modificada | Alta (8.8) | 0.74% | — | Cisco Asyncos | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This… | |
| Modificada | Media (6.5) | 0.80% | — | Cisco Asyncos | 4/11/2022 | 17/6/2026 | A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This… | |
| Modificada | Alta (7.5) | 1.3% | — | Asyncua Project AsyncuaOpcua Project Opcua | 23/8/2022 | 17/6/2026 | All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks… | |
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | Syntacticsinc Easync | 11/7/2022 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid… | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Asyncos | 6/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the… | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Asyncos | 6/4/2022 | 17/6/2026 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a… | |
| Modificada | Alta (7.8) | 3.3% | — | Async Project AsyncFedoraproject Fedora | 6/4/2022 | 17/6/2026 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco Asyncos | 17/2/2022 | 17/6/2026 | A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Asyncos | 4/11/2021 | 17/6/2026 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An… | |
| Modificada | Alta (7.5) | 1.7% | — | Modern-async Project Modern-async | 20/10/2021 | 17/6/2026 | modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Asyncos | 6/10/2021 | 17/6/2026 | A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management in the proxy service of an… | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Asyncos | 6/10/2021 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 0.88% | — | Asyncapi Java-spring-cloud-stream-template | 11/8/2021 | 17/6/2026 | @asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised… | |
| Modificada | Alta (8.1) | 0.77% | — | Async-coap Project Async-coap | 8/8/2021 | 17/6/2026 | An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<RC, T> without trait bounds on RC. | |
| Modificada | Alta (8.8) | 1.9% | — | Cisco WEB Security ApplianceCisco Asyncos | 8/7/2021 | 17/6/2026 | A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An… |