Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.2% | — | Synology Photo Station | 22/3/2018 | 17/6/2026 | Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Synology Photo Station | 22/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Alta (7.5) | 9.0% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+12 | 6/3/2018 | 17/6/2026 | The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association. | |
| Modificada | Alta (7.5) | 8.5% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+6 | 6/3/2018 | 17/6/2026 | ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp.… | |
| Modificada | Media (5.3) | 2.7% | — | NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+5 | 6/3/2018 | 17/6/2026 | ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for… | |
| Modificada | Media (6.5) | 1.8% | — | Synology Surveillance Station | 27/2/2018 | 17/6/2026 | File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter. | |
| Modificada | Media (5.4) | 1.0% | — | Synology Surveillance Station | 27/2/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter. | |
| Modificada | Media (5.3) | 1.9% | — | Synology Photo Station | 23/2/2018 | 17/6/2026 | Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.4) | 1.0% | — | Synology Chat | 28/12/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter. | |
| Modificada | Media (6.5) | 1.6% | — | Synology Chat | 28/12/2017 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI. | |
| Modificada | Media (4.8) | 1.0% | — | Synology Mailplus Server | 27/12/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter. | |
| Modificada | Media (6.5) | 0.74% | — | Synology Diskstation Manager | 22/12/2017 | 17/6/2026 | An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option. | |
| Modificada | Media (5.4) | 1.0% | — | Synology Photo Station | 20/12/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter. | |
| Modificada | Media (4.8) | 0.77% | — | Synology Mailplus Server | 15/12/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter. | |
| Modificada | Media (6.5) | 2.0% | — | Synology Router Manager | 8/12/2017 | 17/6/2026 | Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter. | |
| Modificada | Media (6.5) | 2.0% | — | Synology Diskstation Manager | 8/12/2017 | 17/6/2026 | Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter. | |
| Modificada | Media (6.5) | 1.8% | — | Synology File Station | 8/12/2017 | 17/6/2026 | Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter. | |
| Modificada | Media (6.5) | 1.0% | — | Synology Calendar | 8/12/2017 | 17/6/2026 | Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors. | |
| Modificada | Alta (8.8) | 74% | 💥 Exploit | Synology Diskstation Manager | 4/12/2017 | 17/6/2026 | Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field. | |
| Modificada | Media (5.3) | 1.4% | — | Synology Photo Station | 4/12/2017 | 17/6/2026 | An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file. | |
| Modificada | Alta (7.5) | 1.8% | — | Synology Photo Station | 4/12/2017 | 17/6/2026 | Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field. | |
| Modificada | Crítica (9.8) | 1.9% | — | Synology Carddav Server | 7/11/2017 | 17/6/2026 | An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack. | |
| Modificada | Media (5.4) | 1.1% | — | Synology Audio Station | 30/10/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web script or HTML via the NAME parameter. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+17 | 4/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. |