Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.5% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources… | |
| Modificada | Alta (7.5) | 0.66% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Westerndigital WD MY Book Firmware | 18/9/2019 | 17/6/2026 | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me. | |
| Modificada | Crítica (9.8) | 30% | — | Westerndigital MY Book Live Firmware | 19/6/2019 | 17/6/2026 | Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021… | |
| Modificada | Alta (8.8) | 3.0% | — | Westerndigital MY Cloud FirmwareWesterndigital MY Cloud Mirror Gen2 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Ex2100 Firmware+5 | 23/5/2019 | 17/6/2026 | Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks.… | |
| Modificada | Crítica (9.8) | 2.3% | — | Westerndigital MY Cloud FirmwareWesterndigital MY Cloud Mirror Gen2 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Ex2100 Firmware+5 | 24/4/2019 | 17/6/2026 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file checks credentials against /etc/shadow.… | |
| Modificada | Media (4.6) | 0.34% | — | Westerndigital MY Cloud | 9/10/2018 | 17/6/2026 | There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old account with a new one through special… | |
| Modificada | Crítica (9.8) | 8.4% | — | Westerndigital TV Live HUB FirmwareWesterndigital TV Media Player Firmware | 12/6/2018 | 17/6/2026 | The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi. | |
| Modificada | Crítica (9.8) | 3.6% | — | Westerndigital MY Cloud Firmware | 30/3/2018 | 17/6/2026 | Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud. | |
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Westerndigital MY Cloud Pr4100 Firmware | 12/12/2017 | 17/6/2026 | An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an… | |
| Modificada | Media (5.4) | 0.27% | — | Westerndigital WD MY Cloud | 11/9/2014 | 17/6/2026 | The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Westerndigital Arkeia Virtual Appliance Firmware | 28/4/2014 | 17/6/2026 | Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request… | |
| Modificada | Media (4.3) | 4.6% | 💥 Exploit | Westerndigital MY NET N900Westerndigital MY NET N900cWesterndigital MY NET N750 | 31/7/2013 | 16/6/2026 | main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the "var pass=" line within the HTML source code. |