Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

376 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.0%—ISC BindOpensuse LeapCanonical Ubuntu LinuxSynology DNS Server+121/8/202017/6/2026
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
AnalizadaCrítica (10)99%⚠ Explotación activa💥 ExploitMicrosoft Windows Server 1903Microsoft Windows Server 1909Microsoft Windows Server 2004Microsoft Windows Server 2008+1117/8/202017/6/2026
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the…
ModificadaAlta (7.5)2.5%—Synology Router Manager4/5/202017/6/2026
CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.
ModificadaAlta (8.8)2.6%—Synology Router ManagerBroadcom Bcm4339 Firmware3/2/202017/6/2026
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to…
ModificadaAlta (8.8)3.1%—Synology Router ManagerBroadcom Bcm4339 Firmware3/2/202017/6/2026
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may…
ModificadaMedia (6.5)2.8%—SambaCanonical Ubuntu LinuxSynology Directory ServerSynology Router Manager+321/1/202017/6/2026
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.
ModificadaMedia (6.5)3.2%—SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+621/1/202017/6/2026
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In…
ModificadaAlta (7.5)25%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each…
ModificadaAlta (7.5)28%—Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+1913/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The…
ModificadaMedia (6.5)56%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1513/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and…
ModificadaAlta (7.5)87%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1813/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a…
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaAlta (7.5)82%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1613/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
ModificadaAlta (7.5)60%💥 PoCApple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1613/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to…
ModificadaCrítica (9.8)2.2%—Synology Calendar30/6/201917/6/2026
OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.
ModificadaMedia (5.4)0.71%—Synology Office30/6/201917/6/2026
Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.80%—Synology Note Station30/6/201917/6/2026
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbitrary web script or HTML via the object_id parameter.
ModificadaAlta (8.8)1.7%—Synology Moments30/6/201917/6/2026
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
ModificadaMedia (5.4)0.80%—Synology Calendar30/6/201917/6/2026
Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
ModificadaMedia (6.5)1.3%—Synology Photo Station30/6/201917/6/2026
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
ModificadaCrítica (9.8)1.7%—Synology Photo Station30/6/201917/6/2026
SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.
ModificadaMedia (5.5)0.28%—Synology Calendar9/5/201917/6/2026
Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.
ModificadaAlta (8.1)2.2%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both…
ModificadaAlta (8.1)2.2%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and…
ModificadaBaja (3.7)3.5%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access…
Orbitaley — Vulnerabilidades