Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title. | |
| Modificada | Alta (8.8) | 1.1% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext. | |
| Modificada | Alta (8.8) | 3.4% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter. | |
| Modificada | Alta (8.8) | 3.4% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter. | |
| Modificada | Media (6.5) | 0.68% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password. | |
| Modificada | Alta (7.5) | 2.3% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters. | |
| Modificada | Crítica (9.8) | 4.4% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter. | |
| Modificada | Alta (8.8) | 3.4% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter. | |
| Modificada | Media (5.4) | 0.55% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename. | |
| Modificada | Media (5.4) | 0.55% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature. | |
| Modificada | Alta (7.5) | 1.5% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345. | |
| Modificada | Media (6.5) | 0.59% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter. | |
| Modificada | Alta (8.8) | 3.4% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL parameter, a similar issue to CVE-2018-11344. | |
| Modificada | Media (6.1) | 0.69% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript. | |
| Modificada | Media (6.1) | 0.65% | — | Asustor Data Master | 27/8/2018 | 17/6/2026 | ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field. | |
| Modificada | Media (6.5) | 1.1% | — | Asustor Data Master | 27/8/2018 | 17/6/2026 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi. | |
| Modificada | Media (6.5) | 0.91% | — | Asustor Data Master | 27/8/2018 | 17/6/2026 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history. | |
| Modificada | Media (4.3) | 0.73% | — | Asustor Data Master | 27/8/2018 | 17/6/2026 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi. | |
| Modificada | Media (6.5) | 1.0% | — | Asustor Data Master | 27/8/2018 | 17/6/2026 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi. | |
| Modificada | Alta (7.5) | 1.5% | — | Asustor Data Master | 27/8/2018 | 17/6/2026 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled. | |
| Modificada | Crítica (9.8) | 11% | — | Asustor Data Master | 16/8/2018 | 17/6/2026 | The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI. | |
| Modificada | Crítica (9.8) | 13% | — | Asustor Data Master | 16/8/2018 | 17/6/2026 | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell. |