Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

376 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)3.9%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+417/4/201917/6/2026
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE…
ModificadaMedia (6.1)0.55%—SambaFedoraproject FedoraSynology Directory ServerSynology Router Manager+39/4/201917/6/2026
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded…
ModificadaMedia (6.1)1.1%—Synology WEB Station1/4/201917/6/2026
Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.
ModificadaMedia (6.5)1.4%—Synology Calendar1/4/201917/6/2026
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
ModificadaAlta (8.1)0.94%—Synology Moments1/4/201917/6/2026
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5.3)1.5%—Synology Drive Server1/4/201917/6/2026
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.
ModificadaAlta (7.5)1.8%—Synology Mailplus Server1/4/201917/6/2026
Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct denial-of-service attacks via client-initiated renegotiation.
ModificadaMedia (6.5)1.3%—Synology Application Service1/4/201917/6/2026
Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the version parameter.
ModificadaMedia (6.5)1.3%—Synology Application Service1/4/201917/6/2026
Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter.
ModificadaMedia (5.4)0.80%—Synology Diskstation Manager1/4/201917/6/2026
Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter.
ModificadaMedia (4.3)1.3%—Synology Router Manager1/4/201917/6/2026
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
ModificadaMedia (4.3)1.2%—Synology Diskstation Manager1/4/201917/6/2026
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.
ModificadaMedia (4.3)1.3%—Synology Router Manager1/4/201917/6/2026
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.
ModificadaMedia (5.3)1.6%—Synology Router Manager1/4/201917/6/2026
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
ModificadaMedia (5.3)1.5%—Synology File Station1/4/201917/6/2026
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
ModificadaMedia (6.5)1.3%—Synology Router Manager1/4/201917/6/2026
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
ModificadaMedia (6.5)1.3%—Synology Diskstation Manager1/4/201917/6/2026
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
ModificadaAlta (8.8)2.4%—Synology Router Manager1/4/201917/6/2026
Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
ModificadaAlta (8.8)2.3%—Synology Diskstation Manager1/4/201917/6/2026
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
ModificadaAlta (7.4)1.4%—Synology SSL VPN Client1/4/201917/6/2026
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter.
ModificadaMedia (6.1)1.1%—Synology SSO Server1/4/201917/6/2026
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
ModificadaMedia (5.4)0.81%—Synology Diskstation Manager1/4/201917/6/2026
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.
ModificadaAlta (7.2)1.0%—Synology Diskstation Manager24/12/201817/6/2026
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.
ModificadaCrítica (9.8)1.4%—Synology Diskstation Manager24/12/201817/6/2026
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
ModificadaMedia (5.4)0.80%—Synology Diskstation Manager24/12/201817/6/2026
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
Orbitaley — Vulnerabilidades