Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

376 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.2%—Synology Photo Station22/3/201817/6/2026
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
ModificadaMedia (6.1)1.3%—Synology Photo Station22/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaAlta (7.5)9.0%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+126/3/201817/6/2026
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
ModificadaAlta (7.5)8.5%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+66/3/201817/6/2026
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp.…
ModificadaMedia (5.3)2.7%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+56/3/201817/6/2026
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for…
ModificadaMedia (6.5)1.8%—Synology Surveillance Station27/2/201817/6/2026
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.
ModificadaMedia (5.4)1.0%—Synology Surveillance Station27/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter.
ModificadaMedia (5.3)1.9%—Synology Photo Station23/2/201817/6/2026
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
ModificadaMedia (5.6)94%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (5.4)1.0%—Synology Chat28/12/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.
ModificadaMedia (6.5)1.6%—Synology Chat28/12/201717/6/2026
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
ModificadaMedia (4.8)1.0%—Synology Mailplus Server27/12/201717/6/2026
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
ModificadaMedia (6.5)0.74%—Synology Diskstation Manager22/12/201717/6/2026
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
ModificadaMedia (5.4)1.0%—Synology Photo Station20/12/201717/6/2026
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.
ModificadaMedia (4.8)0.77%—Synology Mailplus Server15/12/201717/6/2026
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
ModificadaMedia (6.5)2.0%—Synology Router Manager8/12/201717/6/2026
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
ModificadaMedia (6.5)2.0%—Synology Diskstation Manager8/12/201717/6/2026
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
ModificadaMedia (6.5)1.8%—Synology File Station8/12/201717/6/2026
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
ModificadaMedia (6.5)1.0%—Synology Calendar8/12/201717/6/2026
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
ModificadaAlta (8.8)74%💥 ExploitSynology Diskstation Manager4/12/201717/6/2026
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
ModificadaMedia (5.3)1.4%—Synology Photo Station4/12/201717/6/2026
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.
ModificadaAlta (7.5)1.8%—Synology Photo Station4/12/201717/6/2026
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
ModificadaCrítica (9.8)1.9%—Synology Carddav Server7/11/201717/6/2026
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
ModificadaMedia (5.4)1.1%—Synology Audio Station30/10/201717/6/2026
Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web script or HTML via the NAME parameter.
ModificadaCrítica (9.8)85%💥 ExploitThekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+174/10/201717/6/2026
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.