Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Synology Diskstation ManagerSynology Photo Station | 12/9/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Disk Pool Manager Project Disk Pool Manager | 13/5/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in LCG Disk Pool Manager (DPM) before 1.8.6, as used in EGI UDM, allow remote attackers to execute arbitrary SQL commands via the (1) r_token variable in the dpm_get_pending_req_by_token, (2) dpm_get_cpr_by_fullid, (3) dpm_get_cpr_by_surl, (4) dpm_get_cpr_by_surls, (5)… | |
| Modificada | Media (6.9) | 0.43% | — | Freedesktop UdisksCanonical Ubuntu Linux | 11/3/2014 | 17/6/2026 | Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point. | |
| Modificada | Alta (7.8) | 1.7% | — | Synology Diskstation Manager | 2/3/2014 | 17/6/2026 | The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session. | |
| Modificada | Alta (10) | 85% | 💥 Exploit | Synology Diskstation Manager | 9/1/2014 | 17/6/2026 | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Synology Diskstation Manager | 31/12/2013 | 17/6/2026 | Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in… | |
| Modificada | Baja (3.5) | 1.4% | — | Iodata Rockdisk FirmwareIodata Rockdisk | 1/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.39% | — | Infotecs Vipnet ClientInfotecs Vipnet CoordinatorInfotecs Vipnet Personal FirewallInfotecs Vipnet Safedisk | 22/5/2013 | 16/6/2026 | Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges… | |
| Modificada | Media (5) | 1.9% | — | LSI 3ware Disk Manager | 15/2/2013 | 16/6/2026 | Directory traversal vulnerability in LSI 3ware Disk Manager (3DM) before 2 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.9) | 0.34% | — | Sophos Safeguard Enterprise Device EncryptionSophos Safeguard Easy Device Encryption ClientSophos Disk Encryption | 24/8/2012 | 16/6/2026 | Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk… | |
| Modificada | Media (4) | 3.1% | — | JAN Kara Linux Diskquota | 13/8/2012 | 16/6/2026 | The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter. | |
| Modificada | Media (6.5) | 5.1% | 💥 Exploit | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet… | |
| Modificada | Alta (10) | 6.6% | — | Symantec Veritas Dynamic Multi-pathingSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System FOR Oracle RACSymantec Netbackup Puredisk | 19/8/2011 | 16/6/2026 | Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier,… | |
| Modificada | Alta (7.8) | 2.0% | — | EMC Disk Library | 2/8/2010 | 16/6/2026 | Unspecified vulnerability in EMC Disk Library (EDL) before 3.2.7, 3.3.x before 3.3.2 epatch 8, and 4.0.x before 4.0.1 epatch 4 allows remote attackers to cause a denial of service (communication-module crash) by sending a crafted message through TCP. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Diskos CMS | 22/4/2010 | 16/6/2026 | Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Diskos CMS | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature. | |
| Modificada | Baja (2.1) | 0.27% | — | Freedesktop Udisks | 12/4/2010 | 16/6/2026 | probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/. | |
| Modificada | Media (4.6) | 0.34% | — | Sandisk Cruzer Enterprise USB | 7/1/2010 | 16/6/2026 | SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time. | |
| Modificada | Media (4.6) | 0.28% | — | Sandisk Cruzer Enterprise Firmware | 7/1/2010 | 16/6/2026 | SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key. | |
| Modificada | Media (4.6) | 0.37% | — | Sandisk Cruzer Enterprise USB | 7/1/2010 | 16/6/2026 | SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program. | |
| Modificada | Alta (9) | 4.1% | — | EMC Diskxtender | 14/4/2008 | 16/6/2026 | Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface. | |
| Modificada | Crítica (9.8) | 4.9% | — | EMC Diskxtender | 14/4/2008 | 16/6/2026 | EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface. | |
| Modificada | Alta (9) | 3.3% | — | EMC Diskxtender | 14/4/2008 | 16/6/2026 | Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface. | |
| Modificada | Alta (7.1) | 23% | 💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP+1 | 27/9/2007 | 16/6/2026 | Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png. |