Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (0.6) | 0.32% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.40% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.40% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (1.3) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Baja (1.3) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Media (4.9) | 0.53% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.30% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Baja (0.6) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Aplazada | Media (4) | 0.16% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 4/2/2026 | 17/6/2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. | |
| Analizada | Media (4.9) | 1.9% | — | Apache Syncope | 3/2/2026 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs. This issue affects… | |
| Analizada | Media (6.8) | 0.51% | — | Apache Syncope | 3/2/2026 | 17/6/2026 | Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3. Users are recommended to upgrade to… | |
| Aplazada | Media (4.3) | 0.18% | — | WP Connect WP Sync FOR NotionAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP connect WP Sync for Notion wp-sync-for-notion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sync for Notion: from n/a through <= 1.7.0. | |
| Analizada | Alta (8.5) | 0.22% | — | Flexense Syncbreeze | 3/2/2026 | 17/6/2026 | Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process. | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Alta (8.2) | 0.40% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious requests to alter the… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.7) | 0.73% | — | Flexense Syncbreeze | 27/1/2026 | 17/6/2026 | SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability. | |
| Analizada | Alta (8.5) | 0.23% | — | Flexense Sync Breeze | 16/1/2026 | 17/6/2026 | Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries located in 'Program Files' directories to inject malicious executables and escalate… |