Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.69% | — | App2pro Airdisk PRO | 24/4/2020 | 17/6/2026 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function. | |
| Modificada | Media (6.1) | 0.70% | — | App2pro Airdisk PRO | 24/4/2020 | 17/6/2026 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function. | |
| Modificada | Crítica (9.8) | 3.9% | — | Diskusage-ng Project Diskusage-ng | 6/4/2020 | 17/6/2026 | diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument. | |
| Modificada | Alta (7.5) | 1.3% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+16 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials. | |
| Modificada | Media (5.5) | 0.19% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+55 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure. | |
| Modificada | Media (6.3) | 0.28% | — | Westerndigital Sandisk X600 Sd9tb8w-128g FirmwareWesterndigital Sandisk X600 Sd9tb8w-256g FirmwareWesterndigital Sandisk X600 Sd9tb8w-512g FirmwareWesterndigital Sandisk X600 Sd9tb8w-1t00 Firmware+55 | 10/3/2020 | 17/6/2026 | Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices. | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. | |
| Modificada | Media (6.5) | 2.8% | — | SambaCanonical Ubuntu LinuxSynology Directory ServerSynology Router Manager+3 | 21/1/2020 | 17/6/2026 | There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer. | |
| Modificada | Media (6.5) | 3.2% | — | SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+6 | 21/1/2020 | 17/6/2026 | All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In… | |
| Modificada | Alta (7.8) | 0.41% | — | Udisks Project UdisksDebian LinuxFedoraproject FedoraOpensuse+1 | 13/11/2019 | 16/6/2026 | udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. | |
| Modificada | Media (5.9) | 1.5% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources… | |
| Modificada | Alta (7.5) | 0.66% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available. | |
| Modificada | Alta (7.5) | 25% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+14 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each… | |
| Modificada | Alta (7.5) | 28% | — | Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+19 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The… | |
| Modificada | Media (6.5) | 56% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+15 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and… | |
| Modificada | Alta (7.5) | 87% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+18 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a… | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+24 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can… | |
| Modificada | Alta (7.5) | 82% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU. | |
| Modificada | Alta (7.5) | 60% | 💥 PoC | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to… | |
| Modificada | Media (6.8) | 0.43% | — | Eye-disk Eyedisk | 12/5/2019 | 17/6/2026 | eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 SCSI command. | |
| Modificada | Media (6.1) | 0.55% | — | SambaFedoraproject FedoraSynology Directory ServerSynology Router Manager+3 | 9/4/2019 | 17/6/2026 | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded… | |
| Modificada | Alta (7.8) | 0.28% | — | Winmagic Securedoc Disk Encryption | 8/4/2019 | 17/6/2026 | WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an attacker to execute arbitrary code on a target system. If the executable is enclosed in quote tags "" then the system will know where to find it. However if the path of where the application binary… | |
| Modificada | Media (5.4) | 0.80% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration. | |
| Modificada | Media (6.5) | 1.3% | — | Synology Diskstation Manager | 1/4/2019 | 17/6/2026 | Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration. |