Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 3.9% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+4 | 17/4/2019 | 17/6/2026 | The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE… | |
| Modificada | Media (6.1) | 0.55% | — | SambaFedoraproject FedoraSynology Directory ServerSynology Router Manager+3 | 9/4/2019 | 17/6/2026 | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded… | |
| Modificada | Media (6.1) | 1.1% | — | Synology WEB Station | 1/4/2019 | 17/6/2026 | Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL. | |
| Modificada | Media (6.5) | 1.4% | — | Synology Calendar | 1/4/2019 | 17/6/2026 | Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter. | |
| Modificada | Alta (8.1) | 0.94% | — | Synology Moments | 1/4/2019 | 17/6/2026 | Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.3) | 1.5% | — | Synology Drive Server | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Synology Mailplus Server | 1/4/2019 | 17/6/2026 | Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct denial-of-service attacks via client-initiated renegotiation. | |
| Modificada | Media (6.5) | 1.3% | — | Synology Application Service | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the version parameter. | |
| Modificada | Media (6.5) | 1.3% | — | Synology Application Service | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Synology Router Manager | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration. | |
| Modificada | Media (4.3) | 1.2% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration. | |
| Modificada | Media (4.3) | 1.3% | — | Synology Router Manager | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter. | |
| Modificada | Media (5.3) | 1.6% | — | Synology Router Manager | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter. | |
| Modificada | Media (5.3) | 1.5% | — | Synology File Station | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter. | |
| Modificada | Media (6.5) | 1.3% | — | Synology Router Manager | 1/4/2019 | 17/6/2026 | Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world readable configuration. | |
| Modificada | Media (6.5) | 1.3% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration. | |
| Modificada | Alta (8.8) | 2.4% | — | Synology Router Manager | 1/4/2019 | 17/6/2026 | Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command. | |
| Modificada | Alta (8.8) | 2.3% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command. | |
| Modificada | Alta (7.4) | 1.4% | — | Synology SSL VPN Client | 1/4/2019 | 17/6/2026 | Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Synology SSO Server | 1/4/2019 | 17/6/2026 | Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (5.4) | 0.81% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter. | |
| Modificada | Alta (7.2) | 1.0% | — | Synology Diskstation Manager | 24/12/2018 | 17/6/2026 | Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format. | |
| Modificada | Crítica (9.8) | 1.4% | — | Synology Diskstation Manager | 24/12/2018 | 17/6/2026 | Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Diskstation Manager | 24/12/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter. |