Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)3.3%💥 ExploitSynology Diskstation ManagerSynology Photo Station12/9/201416/6/2026
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.
ModificadaAlta (7.5)1.5%—Disk Pool Manager Project Disk Pool Manager13/5/201416/6/2026
Multiple SQL injection vulnerabilities in LCG Disk Pool Manager (DPM) before 1.8.6, as used in EGI UDM, allow remote attackers to execute arbitrary SQL commands via the (1) r_token variable in the dpm_get_pending_req_by_token, (2) dpm_get_cpr_by_fullid, (3) dpm_get_cpr_by_surl, (4) dpm_get_cpr_by_surls, (5)…
ModificadaMedia (6.9)0.43%—Freedesktop UdisksCanonical Ubuntu Linux11/3/201417/6/2026
Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
ModificadaAlta (7.8)1.7%—Synology Diskstation Manager2/3/201417/6/2026
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.
ModificadaAlta (10)85%💥 ExploitSynology Diskstation Manager9/1/201417/6/2026
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.
ModificadaAlta (7.5)15%💥 ExploitSynology Diskstation Manager31/12/201317/6/2026
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in…
ModificadaBaja (3.5)1.4%—Iodata Rockdisk FirmwareIodata Rockdisk1/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)0.39%—Infotecs Vipnet ClientInfotecs Vipnet CoordinatorInfotecs Vipnet Personal FirewallInfotecs Vipnet Safedisk22/5/201316/6/2026
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges…
ModificadaMedia (5)1.9%—LSI 3ware Disk Manager15/2/201316/6/2026
Directory traversal vulnerability in LSI 3ware Disk Manager (3DM) before 2 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.9)0.34%—Sophos Safeguard Enterprise Device EncryptionSophos Safeguard Easy Device Encryption ClientSophos Disk Encryption24/8/201216/6/2026
Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk…
ModificadaMedia (4)3.1%—JAN Kara Linux Diskquota13/8/201216/6/2026
The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.
ModificadaMedia (4.3)1.6%💥 ExploitIBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+1422/6/201216/6/2026
Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.
ModificadaMedia (6.5)5.1%💥 ExploitIBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+1422/6/201216/6/2026
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet…
ModificadaAlta (10)6.6%—Symantec Veritas Dynamic Multi-pathingSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System FOR Oracle RACSymantec Netbackup Puredisk19/8/201116/6/2026
Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier,…
ModificadaAlta (7.8)2.0%—EMC Disk Library2/8/201016/6/2026
Unspecified vulnerability in EMC Disk Library (EDL) before 3.2.7, 3.3.x before 3.3.2 epatch 8, and 4.0.x before 4.0.1 epatch 4 allows remote attackers to cause a denial of service (communication-module crash) by sending a crafted message through TCP.
ModificadaMedia (5)2.6%💥 ExploitDiskos CMS22/4/201016/6/2026
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb.
ModificadaAlta (7.5)1.0%💥 ExploitDiskos CMS22/4/201016/6/2026
Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.
ModificadaBaja (2.1)0.27%—Freedesktop Udisks12/4/201016/6/2026
probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
ModificadaMedia (4.6)0.34%—Sandisk Cruzer Enterprise USB7/1/201016/6/2026
SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.
ModificadaMedia (4.6)0.28%—Sandisk Cruzer Enterprise Firmware7/1/201016/6/2026
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
ModificadaMedia (4.6)0.37%—Sandisk Cruzer Enterprise USB7/1/201016/6/2026
SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.
ModificadaAlta (9)4.1%—EMC Diskxtender14/4/200816/6/2026
Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface.
ModificadaCrítica (9.8)4.9%—EMC Diskxtender14/4/200816/6/2026
EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.
ModificadaAlta (9)3.3%—EMC Diskxtender14/4/200816/6/2026
Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface.
ModificadaAlta (7.1)23%💥 ExploitMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP+127/9/200716/6/2026
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
Orbitaley — Vulnerabilidades