Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.2% | — | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.48% | — | Synology Active Backup FOR Business Agent | 13/2/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing… | |
| Analizada | Media (6.5) | 0.40% | — | Synology Active Backup FOR Business Agent | 13/2/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors. | |
| Analizada | Media (6.5) | 0.57% | — | Synology Active Backup FOR Business Agent | 13/2/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified… | |
| Analizada | Alta (7.5) | 0.56% | — | Synology Media Server | 18/12/2024 | 17/6/2026 | Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors. | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive… | |
| Analizada | Media (5.9) | 0.27% | — | Synology Router Manager | 9/12/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and… | |
| Analizada | Alta (8.1) | 0.65% | — | Synology Router Manager | 4/12/2024 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors. | |
| Analizada | Media (4.3) | 0.40% | — | Synology Surveillance Station | 4/12/2024 | 17/6/2026 | Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors. | |
| Analizada | Media (4.3) | 0.40% | — | Synology Surveillance Station | 4/12/2024 | 17/6/2026 | Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors. | |
| Modificada | Crítica (9.8) | 28% | — | Synology PhotosSynology Beephotos | 15/11/2024 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (5.3) | 0.08% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors. | |
| Analizada | Media (5.5) | 0.18% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors. | |
| Analizada | Media (5) | 0.08% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors. | |
| Analizada | Baja (3.3) | 0.16% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout. | |
| Analizada | Alta (8.2) | 0.54% | — | Synology Drive Client | 26/9/2024 | 17/6/2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to overwrite trivial buffers and crash the client via unspecified vectors. | |
| Analizada | Media (4.4) | 0.17% | — | Synology Drive Client | 26/9/2024 | 17/6/2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors. | |
| Analizada | Media (4.4) | 0.17% | — | Synology Drive Client | 26/9/2024 | 17/6/2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors. | |
| Analizada | Media (6.7) | 0.21% | — | Synology Drive Client | 26/9/2024 | 17/6/2026 | Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to execute arbitrary commands via unspecified vectors. | |
| Analizada | Alta (7.8) | 0.20% | — | Synology Drive Client | 26/9/2024 | 17/6/2026 | Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code via unspecified vectors. |