Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Alta (8.2) | 0.40% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious requests to alter the… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Aplazada | Alta (8.5) | 0.17% | — | Disksorter Disk Sorter ServerAI | 16/1/2026 | 17/6/2026 | Disk Sorter Server 13.6.12 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Sorter Server\bin\disksrs.exe' to inject malicious executables and escalate… | |
| Aplazada | Alta (8.5) | 0.17% | — | Diskboss ServiceAI | 16/1/2026 | 17/6/2026 | DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level access during service… | |
| Analizada | Alta (8.5) | 0.23% | — | Flexense Disk Sorter | 16/1/2026 | 17/6/2026 | Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Sorter Enterprise\bin\disksrs.exe' to inject malicious executables and… | |
| Analizada | Alta (8.5) | 0.24% | — | Flexense Disksavvy | 16/1/2026 | 17/6/2026 | Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to inject malicious executables that will be run with elevated LocalSystem privileges. | |
| Analizada | Alta (8.5) | 0.24% | — | Flexense Diskpulse | 16/1/2026 | 17/6/2026 | DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject malicious executables and… | |
| Aplazada | Alta (7.3) | 0.18% | — | Yandex DiskAI | 9/12/2025 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects Disk: before 3.2.45.3275. | |
| Analizada | Alta (8.7) | 0.62% | — | Flexense Diskboss | 5/12/2025 | 17/6/2026 | Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application. | |
| Analizada | Alta (8.6) | 0.37% | — | Flexense Diskboss | 5/12/2025 | 17/6/2026 | Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the system. Attackers can exploit this by pasting a specially crafted directory path into the 'Add Input Directory' field. | |
| Analizada | Alta (8.6) | 0.24% | — | Flexense Diskboss | 5/12/2025 | 17/6/2026 | Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute arbitrary code on the system. | |
| Aplazada | Alta (8.5) | 0.27% | — | Flexense DiskbossAI | 5/12/2025 | 17/6/2026 | Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc'… | |
| Analizada | Alta (8.8) | 0.38% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via… | |
| Analizada | Alta (7.5) | 0.48% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors. | |
| Analizada | Crítica (9.6) | 0.37% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Aplazada | Alta (8.8) | 0.12% | — | Acronis True ImageAIAcronis True Image FOR SandiskAIAcronis True Image FOR Western DigitalAIAcronis True Image OEMAI | 30/9/2025 | 17/6/2026 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198, Acronis True Image for Western Digital (macOS) before build 42197, Acronis True Image OEM (macOS) before… | |
| Aplazada | Alta (7.3) | 0.18% | — | Acronis True ImageAIAcronis True Image FOR Western DigitalAIAcronis True Image FOR SandiskAIAcronis True Image OEMAI | 30/9/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386, Acronis True Image for Western Digital (Windows) before build 42636, Acronis True Image for SanDisk (Windows) before build 42679, Acronis True Image OEM (Windows) before… | |
| Aplazada | Alta (8.5) | 0.65% | — | UdisksAI | 28/8/2025 | 25/9/2026 | A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index… | |
| Analizada | Media (5.3) | 0.33% | — | Diskoverdata Diskover | 27/8/2025 | 17/6/2026 | diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST parameters such as ES_PASS, ES_MAXSIZE, ES_TRANSLOGSIZE, ES_TIMEOUT, ES_USER, ES_HOST, ES_PORT, ES_SCROLLSIZE, ES_CHUNKSIZE and others can be… | |
| Analizada | Media (5.6) | 0.24% | — | Diskoverdata Diskover | 27/8/2025 | 17/6/2026 | diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE, ES_TRANSLOGSYNCINT, EXCLUDES_FILES, FILE_TYPES[],… |