Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests. | |
| Modificada | Crítica (9.8) | 1.1% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator Firmware | 28/3/2019 | 17/6/2026 | ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to initiate a remote reboot, which may be used to cause a denial of service condition. | |
| Modificada | Alta (7.5) | 3.5% | — | Seagate Personal Cloud Firmware | 28/4/2018 | 17/6/2026 | Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url. | |
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 110 Firmware | 23/2/2018 | 17/6/2026 | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php. | |
| Modificada | Crítica (9.8) | 2.7% | — | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 110 Firmware | 23/2/2018 | 17/6/2026 | backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Seagate Personal Cloud Firmware | 12/1/2018 | 17/6/2026 | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled. | |
| Modificada | Media (4.2) | 0.33% | — | Seagate St500lt015 Firmware | 27/11/2017 | 17/6/2026 | Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector to exposed pins, maintaining an alternate power source, and attaching the data… | |
| Modificada | Media (4.2) | 0.33% | — | Samsung 850 PRO FirmwareSamsung Pm851 FirmwareSeagate St500lt015 FirmwareSeagate St500lt025 Firmware | 27/11/2017 | 17/6/2026 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, or in Opal or eDrive mode on Dell Latitude E6410 laptops with BIOS A16 or… | |
| Modificada | Media (4.2) | 0.33% | — | Samsung 850 PRO FirmwareSamsung Pm851 FirmwareSeagate St500lt015 FirmwareSeagate St500lt025 Firmware | 27/11/2017 | 17/6/2026 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with… | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Seagate Blackarmor NAS 220 Firmware | 11/10/2017 | 17/6/2026 | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php. | |
| Modificada | Crítica (9.8) | 44% | 💥 Exploit | Seagate Business NAS Firmware | 8/6/2017 | 17/6/2026 | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens. | |
| Modificada | Alta (8.8) | 2.8% | — | Lacie Lac9000436u FirmwareLacie Lac9000464u FirmwareSeagate Wireless Mobile StorageSeagate Wireless Plus Mobile Storage+1 | 31/12/2015 | 17/6/2026 | Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session. | |
| Modificada | Alta (7.5) | 3.2% | — | Seagate Goflex SatteliteSeagate Wireless Mobile StorageSeagate Wireless Plus Mobile StorageLacie Lac9000436u Firmware+1 | 31/12/2015 | 17/6/2026 | Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session. | |
| Modificada | Crítica (9.8) | 4.2% | — | Seagate Wireless Mobile StorageSeagate Wireless Plus Mobile StorageLacie Lac9000436u FirmwareLacie Lac9000464u Firmware+1 | 31/12/2015 | 17/6/2026 | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session. | |
| Modificada | Media (6.8) | 1.4% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 220 | 21/1/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3)… | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 220 | 9/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php. | |
| Modificada | Alta (10) | 4.4% | — | Seagate Blackarmor NAS | 25/5/2012 | 16/6/2026 | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors. | |
| Modificada | Alta (9.3) | 2.5% | — | Esoft Instagate EX2 UTM | 15/7/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer | |
| Modificada | Alta (7.5) | 1.4% | — | Esoft Instagate EX2 UTM | 15/7/2007 | 16/6/2026 | The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, making a password change from an unattended workstation, or other attacks. | |
| Modificada | Alta (7.6) | 1.3% | — | Esoft Instagate EX2 UTM | 15/7/2007 | 16/6/2026 | The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document. |