Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.90% | — | Westerndigital IBIWesterndigital MY Cloud Home | 15/4/2020 | 17/6/2026 | Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. | |
| Modificada | Crítica (9.1) | 1.00% | — | Western Digital IBIWestern Digital MY Cloud Home | 20/2/2020 | 17/6/2026 | Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation. | |
| Modificada | Alta (8.8) | 2.2% | — | Western Digital MY Cloud EX2 Ultra Firmware | 13/11/2019 | 17/6/2026 | Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters. | |
| Modificada | Alta (8.8) | 3.2% | — | Western Digital MY Cloud EX2 Ultra Firmware | 13/11/2019 | 17/6/2026 | Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs. | |
| Modificada | Alta (8.8) | 2.9% | — | Western Digital MY Cloud EX2 Ultra Firmware | 13/11/2019 | 17/6/2026 | Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow. | |
| Modificada | Alta (8.8) | 3.0% | — | Westerndigital MY Cloud FirmwareWesterndigital MY Cloud Mirror Gen2 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Ex2100 Firmware+5 | 23/5/2019 | 17/6/2026 | Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks.… | |
| Modificada | Crítica (9.8) | 1.7% | — | Western Digital MY Cloud Mirror GEN 2 FirmwareWestern Digital MY Cloud EX2 Ultra FirmwareWestern Digital MY Cloud Ex2100 FirmwareWestern Digital MY Cloud Ex4100+5 | 24/4/2019 | 17/6/2026 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed… | |
| Modificada | Crítica (9.8) | 2.3% | — | Westerndigital MY Cloud FirmwareWesterndigital MY Cloud Mirror Gen2 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Ex2100 Firmware+5 | 24/4/2019 | 17/6/2026 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file checks credentials against /etc/shadow.… | |
| Modificada | Media (4.6) | 0.34% | — | Westerndigital MY Cloud | 9/10/2018 | 17/6/2026 | There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old account with a new one through special… | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Western Digital MY Cloud Wdbctl0020hwt FirmwareWestern Digital MY Cloud Pr4100Western Digital MY Cloud Pr2100 FirmwareWestern Digital MY Cloud Mirror GEN 2 Firmware+8 | 18/9/2018 | 17/6/2026 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an… | |
| Modificada | Crítica (9.8) | 3.6% | — | Westerndigital MY Cloud Firmware | 30/3/2018 | 17/6/2026 | Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud. | |
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Westerndigital MY Cloud Pr4100 Firmware | 12/12/2017 | 17/6/2026 | An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an… | |
| Modificada | Media (5.4) | 0.27% | — | Westerndigital WD MY Cloud | 11/9/2014 | 17/6/2026 | The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |