Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.51% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list… | |
| Pendiente de análisis | Crítica (9.1) | 0.39% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./… | |
| Pendiente de análisis | Alta (7.1) | 0.31% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set… | |
| Analizada | Crítica (9.1) | 0.50% | — | Samba Rsync | 13/8/2026 | 31/8/2026 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the… | |
| Pendiente de análisis | Crítica (9.2) | 0.63% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline… | |
| Analizada | Alta (7.1) | 0.36% | — | Samba Rsync | 13/8/2026 | 31/8/2026 | rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer… | |
| Pendiente de análisis | Media (6.9) | 0.27% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters into names communicated over the… | |
| Analizada | Media (6.9) | 0.40% | — | Samba Rsync | 13/8/2026 | 31/8/2026 | rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon… | |
| Pendiente de análisis | Media (6.9) | 0.19% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating… | |
| Analizada | Alta (8.4) | 0.24% | — | Samba Rsync | 13/8/2026 | 31/8/2026 | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks… | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | RsyncAI | 13/8/2026 | 8/9/2026 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers… | |
| Aplazada | Media (5.3) | 0.34% | — | Order Sync With Zendesk FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer… | |
| Aplazada | Alta (7.5) | 0.74% | — | Asyncfuncai Deepwiki-openAI | 11/8/2026 | 28/8/2026 | A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path parameter and returns a directory listing… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Use-reducer-asyncAI | 10/8/2026 | 8/9/2026 | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21e88cafabfb that executed remote attacker-controlled code on developer machines… | |
| Aplazada | Crítica (9.8) | 0.79% | — | Asyncfuncai Deepwiki-openAI | 10/8/2026 | 28/8/2026 | An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner, repo, and repo_type fields without… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Nasa Ammos Asynchronous Network Management SystemAI | 5/8/2026 | 26/8/2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access… | |
| Aplazada | Alta (8.8) | 0.95% | — | Lightsync PROAI | 5/8/2026 | 12/8/2026 | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the… | |
| Aplazada | Alta (8.5) | 0.17% | — | Asustor Backup PlanAIAsustor EzsyncAI | 4/8/2026 | 3/9/2026 | The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any authenticated local user can recover the key and forge valid… | |
| Aplazada | Media (6.5) | 0.34% | — | Syncpostwithothersite Sync Post With Other SiteAI | 30/7/2026 | 30/7/2026 | The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor)… | |
| Analizada | Alta (8.7) | 0.90% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Aplazada | Baja (1.9) | 1.1% | — | Syncfusion Ej2-javascript-ui-controlsAI | 22/7/2026 | 23/7/2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.3) | 0.39% | — | Electric Postgres SyncAI | 21/7/2026 | 23/7/2026 | Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data… |