Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.25% | — | IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI | 18/9/2026 | 18/9/2026 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of… | |
| En análisis | Baja (3.1) | 0.15% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation… | |
| Pendiente de análisis | Alta (8.1) | 0.52% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks. | |
| En análisis | Baja (3.1) | 0.25% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets. | |
| En análisis | Baja (3.1) | 0.24% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of… | |
| En análisis | Media (6.5) | 0.45% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized system access. | |
| En análisis | Media (6.4) | 0.29% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise. | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files. | |
| Pendiente de análisis | Alta (7.1) | 0.12% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.7) | 0.37% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks. | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | |
| Pendiente de análisis | Media (4.3) | 0.42% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks. | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched. | |
| Pendiente de análisis | Media (5.3) | 0.38% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information. | |
| Pendiente de análisis | Media (6.5) | 0.42% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information. | |
| Pendiente de análisis | Media (4.3) | 0.44% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks. | |
| Pendiente de análisis | Alta (8) | 0.49% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted. | |
| En análisis | Media (5) | 0.16% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries. | |
| Pendiente de análisis | Crítica (9.8) | 0.60% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (2.7) | 0.32% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive… | |
| Pendiente de análisis | Alta (8.8) | 0.39% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.5) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL. | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information. |