Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.55% | — | Synology Drive Client | 26/9/2024 | 17/6/2026 | Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Analizada | Alta (7.5) | 0.67% | — | Synology Tc500 FirmwareSynology Bc500 Firmware | 28/6/2024 | 17/6/2026 | A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500. | |
| Analizada | Alta (7.5) | 0.27% | — | Synology Router Manager | 28/6/2024 | 17/6/2026 | Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (5.9) | 0.52% | — | Synology Router Manager | 28/6/2024 | 17/6/2026 | Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors. | |
| Analizada | Media (4.9) | 0.87% | — | Synology Bc500 FirmwareSynology Tc500 Firmware | 28/6/2024 | 17/6/2026 | A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be… | |
| Analizada | Alta (7.2) | 1.5% | — | Synology Bc500 FirmwareSynology Tc500 Firmware | 28/6/2024 | 17/6/2026 | A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera… | |
| Analizada | Crítica (9.8) | 1.4% | — | Synology Bc500 FirmwareSynology Tc500 Firmware | 28/6/2024 | 17/6/2026 | A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions… | |
| Analizada | Media (5.3) | 0.72% | — | Synology Bc500 FirmwareSynology Tc500 Firmware | 28/6/2024 | 17/6/2026 | A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers to read specific files containing non-sensitive information via unspecified vectors. The following models with Synology Camera Firmware… | |
| Analizada | Alta (7.2) | 1.5% | — | Synology Bc500 FirmwareSynology Tc500 Firmware | 28/6/2024 | 17/6/2026 | A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology… | |
| Analizada | Media (6.5) | 0.41% | — | Synology Bc500 FirmwareSynology Tc500 Firmware | 4/6/2024 | 17/6/2026 | A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. This attack only… | |
| Analizada | Crítica (9.9) | 0.76% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors. | |
| Analizada | Media (4.3) | 0.68% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via unspecified vectors. | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Media (5.4) | 0.65% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Alta (7.7) | 0.80% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Analizada | Alta (7.7) | 0.80% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… |