Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.20% | — | Synology Beedrive | 4/12/2025 | 25/9/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Alta (7.5) | 0.41% | — | Synology Beedrive | 4/12/2025 | 25/9/2026 | Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors. | |
| Analizada | Alta (7.8) | 0.18% | — | Synology Beedrive | 4/12/2025 | 25/9/2026 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (6.3) | 0.37% | — | Synology Mail Server | 4/12/2025 | 25/9/2026 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. | |
| Analizada | Alta (7.2) | 0.64% | — | Synology Router Manager | 4/12/2025 | 25/9/2026 | A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. | |
| Analizada | Media (4.3) | 0.43% | — | Synology Router Manager | 4/12/2025 | 25/9/2026 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. | |
| Analizada | Media (4.3) | 0.43% | — | Synology Router Manager | 4/12/2025 | 25/9/2026 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. | |
| Analizada | Media (5.4) | 0.37% | — | Synology Router Manager | 4/12/2025 | 25/9/2026 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. | |
| Analizada | Alta (8.8) | 0.38% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via… | |
| Analizada | Alta (7.5) | 0.48% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors. | |
| Analizada | Crítica (9.6) | 0.37% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Aplazada | Media (5.9) | 0.28% | — | Synology Radius ServerAI | 29/8/2025 | 26/9/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or write limited files in SRM and conduct limited denial-of-service via unspecified vectors. | |
| Analizada | Media (5.9) | 0.21% | — | Synology Router Manager | 23/7/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Media (5.9) | 0.21% | — | Synology Router Manager | 23/7/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Alta (7.2) | 1.1% | — | Synology Router Manager | 23/7/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to execute arbitrary code via unspecified vectors. | |
| Aplazada | Alta (7.1) | 0.40% | — | Synology File StationAI | 6/6/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Modificada | Media (6.5) | 1.1% | 💥 PoC | Synology Active Backup FOR Microsoft 365 | 16/5/2025 | 17/6/2026 | A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. | |
| Analizada | Alta (7.5) | 0.53% | — | Synology Diskstation Manager | 23/4/2025 | 17/6/2026 | Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Analizada | Alta (7.5) | 26% | — | Synology Drive Server | 19/3/2025 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unspecified vectors. | |
| Analizada | Alta (7.5) | 25% | — | Synology Drive Server | 19/3/2025 | 17/6/2026 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors. | |
| Analizada | Media (5.3) | 32% | 💥 PoC | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors. | |
| Analizada | Crítica (9.8) | 0.77% | — | Synology Tc500 FirmwareSynology Cc400w FirmwareSynology Bc500 Firmware | 19/3/2025 | 17/6/2026 | A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500. | |
| Analizada | Crítica (10) | 1.4% | — | Synology Unified ControllerSynology Replication ServiceSyncology Replication Service | 19/3/2025 | 17/6/2026 | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via… | |
| Analizada | Media (5.3) | 0.37% | — | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors. | |
| Analizada | Alta (7.5) | 0.25% | — | Synology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors. |