« Volver al listado

Sync-in

Sync-in Server: vulnerabilidades y CVE

Sync-in Server tiene 7 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses6
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-58272Media (5.3)0.34%—21 sept 2026
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for…
CVE-2026-58270Media (6.5)0.35%—21 sept 2026
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity…
CVE-2026-58269Alta (8.1)0.22%—21 sept 2026
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`,…
CVE-2026-47684Alta (7.7)0.38%—16 jun 2026
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped…
CVE-2026-41161Media (6.9)0.46%—8 may 2026
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote…
CVE-2025-67438Media (6.1)0.28%—20 feb 2026
A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to execute arbitrary JavaScript in a victim's browser. By uploading a crafted SVG file containing a…
CVE-2025-56869Media (5.3)0.74%—19 sept 2025
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services2
  2. T1078.001 Default Accounts1
  3. T1190 Exploit Public-Facing Application1
  4. T1499.004 Application or System Exploitation1
  5. T1589.001 Credentials1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Sync-in