Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.30% | — | Laci SynchroniAI | 11/9/2026 | 30/9/2026 | Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications`… | |
| Aplazada | Crítica (9.8) | 0.58% | — | User Session SynchronizerAI | 15/8/2026 | 20/8/2026 | The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Nasa Ammos Asynchronous Network Management SystemAI | 5/8/2026 | 26/8/2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access… | |
| Aplazada | Media (5.3) | 0.32% | — | Mailercloud-integrate-webforms-synchronize-contactsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-synchronize-contacts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mailercloud – Integrate webforms and synchronize website… | |
| Aplazada | Alta (7.1) | 0.18% | — | Parisholley Asynchronous JavascriptAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paris Holley Asynchronous Javascript asynchronous-javascript allows Reflected XSS.This issue affects Asynchronous Javascript: from n/a through <= 1.3.5. | |
| Analizada | Media (5.3) | 0.25% | — | Synchronize Composer.json With Contrib Modules Project Synchronize Composer.json With Contrib Modules | 10/10/2025 | 30/9/2026 | Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*. | |
| Analizada | Media (5.4) | 0.31% | — | Synchroweb Kiwire | 10/10/2025 | 17/6/2026 | The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website. | |
| Analizada | Alta (7.3) | 0.39% | — | Synchroweb Kiwire | 10/10/2025 | 17/6/2026 | The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution. | |
| Analizada | Alta (7.3) | 0.29% | — | Synchroweb Kiwire | 10/10/2025 | 17/6/2026 | The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database. | |
| Aplazada | Alta (8.5) | 0.51% | — | FTP Synchronizer ProfessionalAI | 21/8/2025 | 16/6/2026 | A stack-based buffer overflow exists in FTP Synchronizer Professional <= v4.0.73.274. When the client connects to an FTP server and issues a LIST command—typically during sync preview or profile creation—the server’s response containing an overly long filename triggers a buffer overflow. This results in the corruption… | |
| Aplazada | Alta (7.1) | 0.19% | — | Rafasashi User Session SynchronizerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer user-session-synchronizer allows Stored XSS.This issue affects User Session Synchronizer: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Master Software Solutions WP Vtiger SynchronizationAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1. | |
| Aplazada | Media (5.4) | 0.21% | — | Wpsynchro WP SynchroAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DAEV.Tech WP Migration Plugin DB & Files – WP Synchro.This issue affects WP Migration Plugin DB & Files – WP Synchro: from n/a through 1.11.2. | |
| Aplazada | Alta (8.8) | 1.2% | — | Bosch Network SynchronizerAI | 25/3/2024 | 17/6/2026 | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device. | |
| Analizada | Alta (7.8) | 0.41% | — | Relative Synchrony | 17/10/2023 | 17/6/2026 | Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties… | |
| Modificada | Alta (8.8) | 0.31% | — | Wpsynchro WP Synchro | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPSynchro WP Synchro plugin <= 1.9.1 versions. | |
| Modificada | Crítica (9.8) | 1.9% | — | Asynchronous Sockets FOR C++ Project Asynchronous Sockets FOR C++ | 21/7/2023 | 17/6/2026 | async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets. | |
| Modificada | Media (6.1) | 0.22% | — | SAP Master Data Synchronization | 13/6/2023 | 17/6/2026 | An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system. | |
| Modificada | Alta (7.5) | 0.44% | — | IBM Qradar Data Synchronization | 6/5/2023 | 17/6/2026 | IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370. | |
| Modificada | Media (5.4) | 0.59% | — | Pega Synchronization Engine | 10/4/2023 | 17/6/2026 | A man in the middle can redirect traffic to a malicious server in a compromised configuration. | |
| Modificada | Media (6.5) | 1.4% | — | Pega Synchronization Engine | 10/4/2023 | 17/6/2026 | A user with a compromised configuration can start an unsigned binary as a service. | |
| Modificada | Alta (7.8) | 0.17% | — | Pega Synchronization Engine | 10/4/2023 | 17/6/2026 | A user with non-Admin access can change a configuration file on the client to modify the Server URL. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Security Verify Password Synchronization | 27/4/2022 | 17/6/2026 | IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID:… | |
| Modificada | Media (6.5) | 1.1% | — | IBM Security Verify Password Synchronization | 27/4/2022 | 17/6/2026 | IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID:… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… |