Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.27% | — | Qnap Hybrid Backup Sync | 2/1/2026 | 25/7/2026 | An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup… | |
| Analizada | Alta (7) | 0.24% | — | Qnap Hybrid Backup Sync | 2/1/2026 | 17/6/2026 | A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid… | |
| Aplazada | Media (4.4) | 0.12% | — | Qnap Qfinder PRO MACAIQnap Qsync MACAIQnap Qvpn Device Client MACAI | 2/1/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and… | |
| Aplazada | Alta (7.6) | 0.33% | — | Captivateaudio Captivate SyncAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2. | |
| Analizada | Crítica (10) | 32% | ⚠ Explotación activa💥 PoC | Cisco Asyncos | 17/12/2025 | 17/6/2026 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient… | |
| Aplazada | Alta (8.7) | 0.49% | — | Flexense SyncbreezeAI | 15/12/2025 | 17/6/2026 | SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability. | |
| Aplazada | Media (5.3) | 0.28% | — | OpenrsyncAIOpenbsdAI | 15/12/2025 | 17/6/2026 | openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length of zero for block data, because the relationship between p->rem and p->len is not checked. | |
| Aplazada | Media (4.3) | 0.38% | — | Marcoingraiti Actionwear-products-syncAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Actionwear products sync: from n/a through <= 2.3.3. | |
| Analizada | Baja (2.1) | 0.36% | — | Verysync | 7/12/2025 | 17/6/2026 | A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration Module. Executing manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit… | |
| Analizada | Media (5.5) | 0.46% | — | Verysync | 7/12/2025 | 17/6/2026 | A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummytoken of the component Web Administration Module. Performing manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.40% | — | VerysyncAI | 7/12/2025 | 17/6/2026 | A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/resources/f96956469e7be39d of the component Web Administration Module. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.43% | — | Long2ice Asyncmy | 2/12/2025 | 17/6/2026 | SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys. | |
| Analizada | Alta (7.5) | 0.51% | — | Apache Syncope | 24/11/2025 | 17/6/2026 | Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, the default key value, hard-coded in the source code, is always used. This allows a malicious attacker, once obtained access to the internal… | |
| Analizada | Media (5.5) | 0.22% | — | Redboltz Async Mqtt | 24/11/2025 | 17/6/2026 | Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects. | |
| Aplazada | Media (4.3) | 0.33% | — | RsyncAI | 18/11/2025 | 17/6/2026 | A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue. | |
| Analizada | Media (4) | 0.45% | — | Qnap Qsync Central | 7/11/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.3 ( 2025/08/28 )… | |
| Aplazada | Media (5.3) | 0.27% | — | KiotvietsyncAI | 5/11/2025 | 17/6/2026 | The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in kiotvietsync/includes/public_actions/WebHookAction.php. This makes it possible for unauthenticated attackers to extract the webhook token value… | |
| Aplazada | Media (5.3) | 0.31% | — | Kiotviet SyncAI | 5/11/2025 | 17/6/2026 | The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and sync… | |
| Aplazada | Media (4.3) | 0.20% | — | Kiotviet SyncAI | 5/11/2025 | 17/6/2026 | The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all versions up to, and including, 1.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's config. | |
| Aplazada | Crítica (9.8) | 0.84% | 💥 PoC | Kiotviet SyncAI | 5/11/2025 | 17/6/2026 | The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make… | |
| Aplazada | Alta (8.7) | 0.29% | — | TftpsyncAI | 30/10/2025 | 17/6/2026 | A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses. | |
| Aplazada | Media (4.3) | 0.19% | — | Kiotviet SyncAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Kiotviet KiotViet Sync kiotvietsync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiotViet Sync: from n/a through <= 1.8.5. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Captivateaudio Captivate SyncAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injection.This issue affects Captivate Sync: from n/a through <= 3.0.3. | |
| Modificada | Alta (7.2) | 23% | — | Apache Syncope | 20/10/2025 | 17/6/2026 | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime… | |
| Aplazada | Media (6.4) | 0.26% | — | Async JavascriptAI | 18/10/2025 | 17/6/2026 | The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization checks on the aj_steps AJAX aciton along with a lack on sanitization on the settings saved via the function. This makes it possible for authenticated… |