Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.13% | — | Synology Note Station Client | 3/6/2026 | 22/7/2026 | A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. | |
| Analizada | Alta (7.8) | 0.12% | — | Synology Hyper Backup Explorer | 3/6/2026 | 22/7/2026 | An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Alta (7.8) | 0.12% | — | Synology Active Backup FOR Business Recovery Media Creator | 3/6/2026 | 22/7/2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.5) | 0.09% | — | Synology Storage Manager | 27/5/2026 | 17/6/2026 | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. | |
| Analizada | Baja (2.7) | 0.25% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (4.9) | 0.34% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.25% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (4.9) | 0.23% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (4.9) | 0.34% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.33% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (6.8) | 0.11% | — | Synology Beedrive | 27/5/2026 | 17/6/2026 | Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Assistant | 27/5/2026 | 30/9/2026 | An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Active Backup FOR Business Agent | 27/5/2026 | 30/9/2026 | An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Alta (8.6) | 0.37% | — | Synology Active Backup FOR Business | 27/5/2026 | 30/9/2026 | A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. | |
| Analizada | Alta (7.5) | 0.47% | — | Synology C2 Identity Edge Server | 27/5/2026 | 30/9/2026 | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Activeprotect Agent | 27/5/2026 | 30/9/2026 | Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Crítica (9.8) | 0.53% | — | Synology Diskstation Manager | 27/5/2026 | 30/9/2026 | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). | |
| Analizada | Media (5.4) | 0.25% | — | Synology Contacts | 27/5/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. | |
| Analizada | Crítica (9.8) | 2.8% | — | Synology Beestation OS | 27/5/2026 | 30/9/2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (5.9) | 0.27% | — | Synology Safe Access | 27/5/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited… | |
| Analizada | Alta (7.8) | 0.14% | — | Synology Beedrive | 27/5/2026 | 26/9/2026 | Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Alta (8.1) | 0.32% | — | Synology SSL VPN Client | 10/4/2026 | 17/6/2026 | A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user… | |
| Analizada | Media (6.5) | 0.19% | — | Synology SSL VPN Client | 10/4/2026 | 17/6/2026 | A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may… | |
| Analizada | Alta (7.3) | 0.15% | — | Synology Presto Client | 24/2/2026 | 17/6/2026 | An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Beedrive | 4/12/2025 | 25/9/2026 | Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors. |