Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.80% | — | Synology Router Manager | 24/12/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | NetatalkSynology Router ManagerSynology SkynasSynology Diskstation Manager+2 | 20/12/2018 | 17/6/2026 | Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution. | |
| Modificada | Media (6.3) | 0.96% | — | Synology Photo Station | 31/10/2018 | 17/6/2026 | Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Synology SkynasSynology Vs960hdSynology Diskstation Manager | 31/10/2018 | 17/6/2026 | Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter. | |
| Modificada | Media (5.9) | 0.63% | — | Synology Diskstation Manager | 30/7/2018 | 17/6/2026 | Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.1% | — | Synology Ds107 FirmwareSynology Ds213 FirmwareSynology Ds116 Firmware | 13/7/2018 | 17/6/2026 | Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device. | |
| Modificada | Alta (8.1) | 0.75% | — | Synology SSL VPN Client | 6/7/2018 | 17/6/2026 | Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Carddav Server | 5/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_name, or (3) additional_name parameter. | |
| Modificada | Alta (8.8) | 1.4% | — | Synology Universal Search | 5/7/2018 | 17/6/2026 | Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode. | |
| Modificada | Media (6.5) | 0.91% | — | Synology Calendar | 14/6/2018 | 17/6/2026 | Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Synology Photo Station | 8/6/2018 | 17/6/2026 | Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter. | |
| Modificada | Alta (8.8) | 0.73% | — | Synology Photo Station | 8/6/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) username, (2) password, (3) admin, (4) action, (5) uid, or (6) modify_admin parameter. | |
| Modificada | Alta (8.8) | 0.98% | — | Synology Diskstation Manager | 8/6/2018 | 17/6/2026 | Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification. | |
| Modificada | Alta (7.2) | 2.4% | — | Synology Router Manager | 8/6/2018 | 17/6/2026 | Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter. | |
| Modificada | Alta (7.2) | 1.9% | — | Synology Diskstation Manager | 8/6/2018 | 17/6/2026 | Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Office | 5/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name. | |
| Modificada | Media (5.4) | 0.80% | — | Synology File Station | 5/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments. | |
| Modificada | Media (6.5) | 0.92% | — | Synology Drive Server | 1/6/2018 | 17/6/2026 | Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors. | |
| Modificada | Media (5.4) | 0.62% | — | Synology Drive Server | 1/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Calendar | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Synology Media Server | 10/5/2018 | 17/6/2026 | SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Drive Server | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments. | |
| Modificada | Media (5.4) | 1.0% | — | Synology Note Station | 9/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via the commit_msg parameter. | |
| Modificada | Media (5.4) | 1.0% | — | Synology Note Station | 9/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments. | |
| Modificada | Alta (7.8) | 18% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 8/5/2018 | 17/6/2026 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)… |