Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46). | |
| Modificada | Alta (7.2) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46). | |
| Modificada | Alta (8.8) | 4.5% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46). | |
| Modificada | Crítica (9.8) | 37% | — | Quest Disk Backup | 2/6/2018 | 17/6/2026 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46). | |
| Modificada | Alta (7.8) | 18% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 8/5/2018 | 17/6/2026 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)… | |
| Modificada | Media (6.1) | 0.69% | — | Flexense Disksorter | 2/5/2018 | 17/6/2026 | XSS exists in Flexense DiskSorter Enterprise from v9.5.12 to v10.7. | |
| Modificada | Media (6.1) | 0.69% | — | Flexense Disksavvy | 2/5/2018 | 17/6/2026 | XSS exists in Flexense DiskSavvy Enterprise from v10.4 to v10.7. | |
| Modificada | Media (6.1) | 0.69% | — | Flexense Diskpulse | 2/5/2018 | 17/6/2026 | XSS exists in Flexense DiskPulse Enterprise from v10.4 to v10.7. | |
| Modificada | Media (6.1) | 0.69% | — | Flexense Diskboss | 2/5/2018 | 17/6/2026 | Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS. | |
| Modificada | Alta (7.5) | 9.0% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+12 | 6/3/2018 | 17/6/2026 | The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association. | |
| Modificada | Alta (7.5) | 8.5% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+6 | 6/3/2018 | 17/6/2026 | ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp.… | |
| Modificada | Media (5.3) | 2.7% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+5 | 6/3/2018 | 17/6/2026 | ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for… | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Flexense Disksavvy | 27/2/2018 | 17/6/2026 | A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124. | |
| Modificada | Alta (8.1) | 0.46% | — | Flexense Diskboss | 2/2/2018 | 17/6/2026 | An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server and client disclose sensitive information, such as the authentication credentials, to any… | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Flexense DupscoutFlexense DisksavvyFlexense SyncbreezeFlexense Diskpulse | 24/1/2018 | 17/6/2026 | A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the… | |
| Modificada | Crítica (9.8) | 39% | 💥 Exploit | Flexense Diskboss | 12/1/2018 | 17/6/2026 | A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account. |