Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.25%—Westerndigital Sandisk Security Installer15/11/202317/6/2026
Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges…
ModificadaAlta (7.5)0.88%—Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager13/6/202317/6/2026
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
ModificadaAlta (8.1)0.97%—Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager13/6/202317/6/2026
Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
ModificadaAlta (7.5)0.59%—Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+812/6/202317/6/2026
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102;…
ModificadaMedia (4.9)0.77%—Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware18/5/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo,…
ModificadaCrítica (9.8)1.5%—Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware18/5/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western…
ModificadaMedia (4.9)0.57%—Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware18/5/202317/6/2026
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My…
ModificadaAlta (7.5)1.3%—Savysoda Wifi HD Wireless Disk Drive17/5/202317/6/2026
savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.
ModificadaAlta (7.5)0.30%—Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware10/5/202317/6/2026
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
ModificadaAlta (8.1)0.56%—Westerndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home Firmware10/5/202317/6/2026
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to…
ModificadaMedia (4.3)0.46%—Westerndigital MY CloudWesterndigital MY Cloud HomeWesterndigital MY Cloud OS 5Westerndigital Sandisk IBI8/5/202317/6/2026
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing…
ModificadaAlta (7.4)0.31%—Westerndigital Sandisk Privateaccess24/3/202317/6/2026
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
ModificadaMedia (6.7)0.32%—Baidunetdisk22/12/202217/6/2026
Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.20%—Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware1/12/202217/6/2026
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.
ModificadaAlta (7.8)0.21%—Etm-s Ondiskplayeragent25/11/202217/6/2026
Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attacker could exploit the vulnerability to cause remote code execution by causing an arbitrary user to download and execute malicious code.
ModificadaMedia (4.3)0.33%—Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware9/11/202217/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could…
ModificadaCrítica (9.1)0.85%—Synology Diskstation Manager25/10/202217/6/2026
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.
ModificadaMedia (4.3)0.74%—Synology Diskstation Manager25/10/202217/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.
ModificadaAlta (7.5)1.00%—Synology Diskstation Manager20/10/202217/6/2026
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be…
ModificadaAlta (8.1)1.1%—Synology Diskstation Manager20/10/202217/6/2026
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology…
ModificadaCrítica (9.8)1.6%—Synology Diskstation Manager20/10/202217/6/2026
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager…
ModificadaCrítica (9.8)1.6%—Synology Diskstation Manager20/10/202217/6/2026
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager…
ModificadaMedia (6.7)0.31%—Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware27/9/202217/6/2026
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is…
ModificadaAlta (7.8)0.37%—Kdiskmark Project KdiskmarkFedoraproject Fedora14/9/202217/6/2026
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
ModificadaMedia (6.5)0.20%—Eset Endpoint EncryptionEset Full Disk Encryption6/9/202217/6/2026
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.