Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)9.1%💥 ExploitFlexense Diskboss10/1/201817/6/2026
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
ModificadaAlta (7.5)13%💥 ExploitFlexense Disk Pulse10/1/201817/6/2026
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
ModificadaMedia (5.6)94%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (6.5)0.74%—Synology Diskstation Manager22/12/201717/6/2026
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
ModificadaMedia (6.5)2.0%—Synology Diskstation Manager8/12/201717/6/2026
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
ModificadaAlta (8.8)74%💥 ExploitSynology Diskstation Manager4/12/201717/6/2026
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
ModificadaMedia (4.3)0.42%—Sandisk Secureaccess16/11/201717/6/2026
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes.
ModificadaAlta (7.5)1.2%—Iodata LAN Disk Connect Firmware13/11/201717/6/2026
I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.
ModificadaCrítica (9.8)85%💥 ExploitThekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+174/10/201717/6/2026
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
ModificadaMedia (4.9)1.4%—Synology Diskstation Manager28/8/201717/6/2026
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.
ModificadaMedia (5.3)77%💥 ExploitSynology Diskstation Manager24/7/201717/6/2026
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
ModificadaAlta (7.5)1.4%—Synology Diskstation Manager24/7/201717/6/2026
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
ModificadaMedia (6.5)0.89%—Allen Disk Project Allen Disk31/5/201717/6/2026
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
ModificadaMedia (5.4)0.68%—Allen Disk Project Allen Disk28/5/201717/6/2026
Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php.
ModificadaAlta (7.5)1.3%—Allen Disk Project Allen Disk19/5/201717/6/2026
/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].
ModificadaAlta (7.5)1.3%—Allen Disk Project Allen Disk19/5/201717/6/2026
reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].
ModificadaMedia (6.5)0.49%—Allen Disk Project Allen Disk8/5/201717/6/2026
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
ModificadaMedia (6.1)0.63%—Allen Disk Project Allen Disk8/5/201717/6/2026
Allen Disk 1.6 has XSS in the id parameter to downfile.php.
ModificadaMedia (5.4)0.64%—Iodata Rockdisk Firmware13/4/201717/6/2026
Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-4713.
ModificadaAlta (7.8)54%💥 ExploitFlexense DiskbossFlexense DisksorterFlexense Syncbreeze29/3/201717/6/2026
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a…
ModificadaCrítica (9.8)14%💥 ExploitDisksorter Disk Sorter22/3/201717/6/2026
A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.
ModificadaCrítica (9.8)33%💥 ExploitDisksavvy Enterprise22/2/201717/6/2026
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.
ModificadaMedia (4.3)1.4%—Synology Diskstation Manager18/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) before 5.2-5565 Update 1 allows remote attackers to inject arbitrary web script or HTML via the "compound" parameter to entry.cgi.
ModificadaMedia (5)3.5%—Synology Diskstation Manager1/4/201517/6/2026
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP…
ModificadaBaja (3.6)0.33%—Check Diskio Project Check Diskio28/11/201417/6/2026
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).
Orbitaley — Vulnerabilidades