Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI | 2/3/2026 | 17/6/2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | |
| Aplazada | Alta (7.1) | 0.18% | — | Parisholley Asynchronous JavascriptAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paris Holley Asynchronous Javascript asynchronous-javascript allows Reflected XSS.This issue affects Asynchronous Javascript: from n/a through <= 1.3.5. | |
| Aplazada | Alta (7.5) | 0.27% | — | Saiful Islam Sync Master Sheet Product Sync With Google Sheet FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Saiful Islam Sync Master Sheet – Product Sync with Google Sheet for WooCommerce product-sync-master-sheet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sync Master Sheet – Product Sync with Google Sheet for WooCommerce: from n/a… | |
| Analizada | Media (6.1) | 0.28% | — | Sync-in Server | 20/2/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to execute arbitrary JavaScript in a victim's browser. By uploading a crafted SVG file containing a malicious payload, an attacker can access and exfiltrate sensitive information, including the user's… | |
| Aplazada | Media (4.3) | 0.26% | — | Stellarwp Ithemes SyncAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through <= 3.2.8. | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 )… | |
| Analizada | Baja (1.2) | 0.59% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Baja (1.2) | 0.50% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 )… | |
| Analizada | Baja (1.3) | 0.44% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Baja (3.6) | 0.50% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… | |
| Analizada | Baja (3.6) | 0.50% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… | |
| Analizada | Baja (1.3) | 0.58% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (2.3) | 0.47% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Media (4.9) | 0.52% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (1.3) | 0.40% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 )… | |
| Analizada | Media (4.9) | 0.26% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Media (4.9) | 0.26% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Media (4.9) | 0.26% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Baja (1.3) | 0.50% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Baja (1.3) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Baja (1.3) | 0.50% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Baja (0.6) | 0.50% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Baja (0.6) | 0.40% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later |