Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.3% | — | Synology Diskstation Manager | 12/3/2021 | 17/6/2026 | Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests. | |
| Modificada | Alta (7.8) | 1.1% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller+1 | 26/2/2021 | 17/6/2026 | Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options. | |
| Modificada | Crítica (9) | 1.5% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic. | |
| Modificada | Media (5.9) | 0.74% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session. | |
| Modificada | Alta (8.7) | 0.67% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. | |
| Modificada | Media (6.7) | 0.51% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.9% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. | |
| Modificada | Alta (8.1) | 2.1% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. | |
| Modificada | Alta (7.4) | 0.77% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Crítica (9.8) | 4.6% | — | Synology Safeaccess | 30/11/2020 | 17/6/2026 | SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter. | |
| Modificada | Media (4.8) | 5.2% | — | Synology Safeaccess | 30/11/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Synology Router Manager | 29/10/2020 | 17/6/2026 | Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (5.9) | 0.58% | — | Synology Router Manager | 29/10/2020 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors. | |
| Modificada | Baja (3.7) | 0.55% | — | Synology Diskstation Manager | 29/10/2020 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors. | |
| Modificada | Crítica (10) | 1.8% | — | Synology Router Manager | 29/10/2020 | 17/6/2026 | Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic. | |
| Modificada | Crítica (9.8) | 4.7% | — | Synology Router Manager | 29/10/2020 | 17/6/2026 | Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp. | |
| Modificada | Alta (8.3) | 0.83% | — | Synology Router ManagerSynology Diskstation Manager | 29/10/2020 | 17/6/2026 | Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (8.3) | 0.83% | — | Synology Diskstation ManagerSynology Skynas Firmware | 29/10/2020 | 17/6/2026 | Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (8.1) | 0.77% | — | Synology Router Manager | 29/10/2020 | 17/6/2026 | Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. | |
| Modificada | Baja (3.7) | 0.56% | — | Synology Diskstation ManagerSynology Skynas Firmware | 29/10/2020 | 17/6/2026 | Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. | |
| Modificada | Crítica (9) | 0.72% | — | Synology Router Manager | 29/10/2020 | 17/6/2026 | Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Crítica (9) | 0.72% | — | Synology Diskstation ManagerSynology Skynas Firmware | 29/10/2020 | 17/6/2026 | Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 6.4% | — | ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+3 | 21/8/2020 | 17/6/2026 | In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with… | |
| Modificada | Media (6.5) | 5.6% | — | ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 21/8/2020 | 17/6/2026 | In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an… |