Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.71% | — | Westerndigital Edgerover | 13/1/2022 | 17/6/2026 | File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated… | |
| Modificada | Alta (7.5) | 13% | — | Westerndigital WD MY Book Live FirmwareWesterndigital WD MY Book Live DUO Firmware | 29/6/2021 | 17/6/2026 | Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472. | |
| Modificada | Alta (8.8) | 0.97% | — | Westerndigital Edgerover | 11/6/2021 | 17/6/2026 | Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library… | |
| Modificada | Media (6.5) | 0.89% | — | Westerndigital Armorlock | 19/3/2021 | 17/6/2026 | The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware. | |
| Modificada | Alta (7.8) | 1.0% | 💥 PoC | Westerndigital MY Cloud OS | 10/3/2021 | 17/6/2026 | Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files). | |
| Modificada | Alta (7.8) | 0.43% | — | Westerndigital Dashboard | 12/12/2020 | 17/6/2026 | Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. | |
| Modificada | Crítica (9.8) | 2.9% | — | Westerndigital MY Cloud OS 5 | 12/12/2020 | 17/6/2026 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device. | |
| Modificada | Crítica (9.8) | 3.8% | — | Westerndigital MY Cloud OS 5 | 1/12/2020 | 17/6/2026 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths. | |
| Modificada | Crítica (9.8) | 3.9% | — | Westerndigital MY Cloud OS 5 | 1/12/2020 | 17/6/2026 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to… | |
| Modificada | Crítica (9.8) | 3.9% | — | Westerndigital MY Cloud OS 5 | 1/12/2020 | 17/6/2026 | On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device. | |
| Modificada | Media (6.8) | 0.30% | — | Westerndigital Inand CL Em132 FirmwareWesterndigital Inand IX Em132 FirmwareWesterndigital Inand IX Em132 XI FirmwareTrustedfirmware Op-tee | 18/11/2020 | 17/6/2026 | Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions of eMMC, UFS, and NVMe. The RPMB protocol is specified by industry standards bodies and is implemented by storage devices… | |
| Modificada | Crítica (9.8) | 6.2% | — | Westerndigital MY Cloud Firmware | 29/10/2020 | 17/6/2026 | An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges. | |
| Modificada | Crítica (9.8) | 4.9% | — | Westerndigital MY Cloud Firmware | 27/10/2020 | 17/6/2026 | Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3). | |
| Modificada | Crítica (9.8) | 6.2% | — | Westerndigital MY Cloud Firmware | 27/10/2020 | 17/6/2026 | Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114 | |
| Modificada | Crítica (9.8) | 7.5% | — | Westerndigital MY Cloud Firmware | 27/10/2020 | 17/6/2026 | Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114. | |
| Modificada | Crítica (9.8) | 6.1% | — | Westerndigital MY Cloud Firmware | 27/10/2020 | 17/6/2026 | Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140. | |
| Modificada | Crítica (9.8) | 3.3% | — | Westerndigital MY Cloud Firmware | 27/10/2020 | 17/6/2026 | Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114. | |
| Modificada | Alta (8.8) | 4.1% | — | Westerndigital WD Discovery | 17/7/2020 | 17/6/2026 | In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables. | |
| Modificada | Alta (8.8) | 0.45% | — | Westerndigital WD Discovery | 13/5/2020 | 17/6/2026 | The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space. | |
| Modificada | Media (4.7) | 0.90% | — | Westerndigital IBIWesterndigital MY Cloud Home | 15/4/2020 | 17/6/2026 | Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. | |
| Modificada | Alta (7.5) | 1.3% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+16 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials. | |
| Modificada | Media (5.5) | 0.19% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+55 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure. | |
| Modificada | Media (6.3) | 0.28% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+55 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices. | |
| Modificada | Media (6.1) | 0.86% | — | Westerndigital Mycloud.com | 20/2/2020 | 17/6/2026 | Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS. | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. |