Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.6) | 0.24% | — | Diskoverdata Diskover | 27/8/2025 | 17/6/2026 | diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML response, allowing attackers to inject and execute arbitrary… | |
| Aplazada | Alta (8.6) | 1.4% | — | Disk Pulse EnterpriseAI | 15/7/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a specially crafted HTTP POST request to the /login endpoint with an overly long username parameter, causing a buffer overflow in the libspp.dll component. Successful exploitation… | |
| Aplazada | Crítica (10) | 1.6% | — | Diskboss EnterpriseAI | 15/7/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can… | |
| Aplazada | Alta (7) | 0.47% | — | LibblockdevAIFreedesktop UdisksAI | 19/6/2025 | 30/6/2026 | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able… | |
| Analizada | Alta (7.5) | 0.53% | — | Synology Diskstation Manager | 23/4/2025 | 17/6/2026 | Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Analizada | Media (5.3) | 32% | — | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors. | |
| Analizada | Media (5.3) | 0.37% | — | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors. | |
| Analizada | Alta (7.5) | 0.25% | — | Synology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors. | |
| Analizada | Crítica (9.8) | 1.2% | — | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Alta (7.8) | 0.34% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service. | |
| Analizada | Alta (7.8) | 0.50% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation. | |
| Analizada | Media (5.1) | 0.35% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation. | |
| Analizada | Alta (8.4) | 0.37% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. | |
| Analizada | Alta (7.8) | 0.34% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits. | |
| Modificada | Baja (3.5) | 0.39% | — | Antongorodezkiy Yadisk Files | 25/11/2024 | 17/6/2026 | The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.8) | 0.69% | — | Antongorodezkiy Yadisk Files | 25/11/2024 | 17/6/2026 | The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.5) | 0.16% | — | HPE Nonstop Disk UtilAI | 22/11/2024 | 17/6/2026 | A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series. | |
| Aplazada | Media (5.9) | 0.32% | — | Sandisk IBIAIWesterndigital MY CloudAIWesterndigital MY Cloud HomeAIWesterndigital WD CloudAI | 24/6/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious… | |
| Aplazada | Media (5.3) | 0.33% | — | Qiwen NetdiskAI | 23/5/2024 | 17/6/2026 | A vulnerability was found in Qiwen Netdisk up to 1.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component File Rename Handler. The manipulation with the input <img src="" onerror="alert(document.cookie)"> leads to cross site scripting. The attack can be… | |
| Analizada | Media (6.1) | 0.64% | — | Rainbow External Link Network Disk Project Rainbow External Link Network Disk | 12/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation component of the input parameters. | |
| Analizada | Alta (8.8) | 0.15% | — | Secdiskapp | 8/4/2024 | 17/6/2026 | An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions. | |
| Aplazada | Alta (7.9) | 0.19% | — | Sandisk PrivateaccessAI | 13/3/2024 | 17/6/2026 | A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system user. This vulnerability is only exploitable locally if an attacker has access to a copy of the user's vault or has already gained access into a user's… | |
| Modificada | Media (4.9) | 0.82% | — | Westerndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Mirror G2 Firmware+8 | 5/2/2024 | 17/6/2026 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My… | |
| Modificada | Media (5.5) | 0.24% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+9 | 5/2/2024 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that… | |
| Modificada | Media (5.4) | 0.38% | — | Synology Diskstation Manager | 24/1/2024 | 17/6/2026 | URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors. |