Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.1% | 💥 Exploit | Flexense Diskboss | 10/1/2018 | 17/6/2026 | In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Flexense Disk Pulse | 10/1/2018 | 17/6/2026 | In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (6.5) | 0.74% | — | Synology Diskstation Manager | 22/12/2017 | 17/6/2026 | An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option. | |
| Modificada | Media (6.5) | 2.0% | — | Synology Diskstation Manager | 8/12/2017 | 17/6/2026 | Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter. | |
| Modificada | Alta (8.8) | 74% | 💥 Exploit | Synology Diskstation Manager | 4/12/2017 | 17/6/2026 | Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field. | |
| Modificada | Media (4.3) | 0.42% | — | Sandisk Secureaccess | 16/11/2017 | 17/6/2026 | SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes. | |
| Modificada | Alta (7.5) | 1.2% | — | Iodata LAN Disk Connect Firmware | 13/11/2017 | 17/6/2026 | I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+17 | 4/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | |
| Modificada | Media (4.9) | 1.4% | — | Synology Diskstation Manager | 28/8/2017 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack. | |
| Modificada | Media (5.3) | 77% | 💥 Exploit | Synology Diskstation Manager | 24/7/2017 | 17/6/2026 | An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Synology Diskstation Manager | 24/7/2017 | 17/6/2026 | A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter. | |
| Modificada | Media (6.5) | 0.89% | — | Allen Disk Project Allen Disk | 31/5/2017 | 17/6/2026 | SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter. | |
| Modificada | Media (5.4) | 0.68% | — | Allen Disk Project Allen Disk | 28/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Allen Disk Project Allen Disk | 19/5/2017 | 17/6/2026 | /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha']. | |
| Modificada | Alta (7.5) | 1.3% | — | Allen Disk Project Allen Disk | 19/5/2017 | 17/6/2026 | reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha']. | |
| Modificada | Media (6.5) | 0.49% | — | Allen Disk Project Allen Disk | 8/5/2017 | 17/6/2026 | Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. | |
| Modificada | Media (6.1) | 0.63% | — | Allen Disk Project Allen Disk | 8/5/2017 | 17/6/2026 | Allen Disk 1.6 has XSS in the id parameter to downfile.php. | |
| Modificada | Media (5.4) | 0.64% | — | Iodata Rockdisk Firmware | 13/4/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-4713. | |
| Modificada | Alta (7.8) | 54% | 💥 Exploit | Flexense DiskbossFlexense DisksorterFlexense Syncbreeze | 29/3/2017 | 17/6/2026 | A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a… | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Disksorter Disk Sorter | 22/3/2017 | 17/6/2026 | A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Disksavvy Enterprise | 22/2/2017 | 17/6/2026 | Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request. | |
| Modificada | Media (4.3) | 1.4% | — | Synology Diskstation Manager | 18/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) before 5.2-5565 Update 1 allows remote attackers to inject arbitrary web script or HTML via the "compound" parameter to entry.cgi. | |
| Modificada | Media (5) | 3.5% | — | Synology Diskstation Manager | 1/4/2015 | 17/6/2026 | The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP… | |
| Modificada | Baja (3.6) | 0.33% | — | Check Diskio Project Check Diskio | 28/11/2014 | 17/6/2026 | The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*). |