Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 23/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 23/6/2021 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 23/6/2021 | 17/6/2026 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 23/6/2021 | 17/6/2026 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.0% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 23/6/2021 | 17/6/2026 | Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Synology Calendar | 18/6/2021 | 17/6/2026 | Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4.3) | 0.76% | — | Synology Download Station | 18/6/2021 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.4% | — | Synology Download Station | 18/6/2021 | 17/6/2026 | Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.9% | — | Synology Download Station | 18/6/2021 | 17/6/2026 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.3) | 1.0% | — | Synology Media Server | 18/6/2021 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intranet resources via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.9% | — | Synology Photo Station | 2/6/2021 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Synology Photo Station | 2/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.7% | — | Synology Photo Station | 2/6/2021 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors. | |
| Modificada | Alta (7.7) | 1.0% | — | Synology Download Station | 1/6/2021 | 17/6/2026 | Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.9) | 0.29% | — | Synology Docker | 1/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Synology Diskstation Manager | 1/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors. | |
| Modificada | Crítica (9.1) | 0.97% | — | Synology Video Station | 1/6/2021 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors. | |
| Modificada | Crítica (9.8) | 0.99% | — | Synology Media Server | 1/6/2021 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.7% | — | Synology Photo Station | 1/6/2021 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.32% | — | Synology Diskstation Manager | 1/6/2021 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.3% | — | Synology Diskstation ManagerDebian LinuxNetatalk | 21/5/2021 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of DSI structures in Netatalk. The issue results from the lack of proper… | |
| Modificada | Alta (8.8) | 2.8% | — | Synology Antivirus Essential | 28/4/2021 | 17/6/2026 | Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows remote authenticated users to obtain privilege via unspecified vectors. | |
| Modificada | Alta (7.2) | 2.6% | — | Synology Diskstation Manager | 1/4/2021 | 17/6/2026 | Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter. | |
| Modificada | Crítica (9.8) | 3.2% | — | Synology Diskstation Manager | 12/3/2021 | 17/6/2026 | Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests. | |
| Modificada | Crítica (9.8) | 3.9% | — | Synology Diskstation Manager | 12/3/2021 | 17/6/2026 | Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests. |