Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.52% | — | Samsung Syncthru WEB Service | 22/8/2023 | 17/6/2026 | An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks. | |
| Modificada | Alta (7.5) | 1.8% | — | Samsung Syncthru WEB Service | 20/12/2021 | 17/6/2026 | The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required. | |
| Modificada | Media (6.1) | 1.5% | — | Samsung Syncthru WEB ServiceSamsung X7400gx Firmware | 21/3/2019 | 17/6/2026 | XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.login/gnb/loginView.sws" in multiple parameters: contextpath and basedURL. | |
| Modificada | Media (6.1) | 1.5% | — | Samsung Syncthru WEB ServiceSamsung X7400gx Firmware | 21/3/2019 | 17/6/2026 | XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.application/information/networkinformationView.sws" in the tabName parameter. | |
| Modificada | Media (6.1) | 1.5% | — | Samsung Syncthru WEB ServiceSamsung X7400gx Firmware | 21/3/2019 | 17/6/2026 | XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters: ruiFw_id, ruiFw_pid, ruiFw_title. | |
| Modificada | Media (6.1) | 1.6% | — | Samsung Syncthru WEB ServiceSamsung X7400gx Firmware | 21/3/2019 | 17/6/2026 | XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc. | |
| Modificada | Alta (8.8) | 0.51% | — | Samsung Syncthru WEB Service | 3/8/2018 | 17/6/2026 | Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action. | |
| Modificada | Media (6.1) | 0.69% | — | Samsung Syncthru WEB Service | 3/8/2018 | 17/6/2026 | Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid. |