Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Drobo 5N2 Firmware | 24/2/2020 | 17/6/2026 | In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications, but also poses… | |
| Modificada | Crítica (9.8) | 1.9% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation. | |
| Modificada | Crítica (9.8) | 1.3% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic. | |
| Modificada | Alta (7.5) | 28% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations. | |
| Modificada | Crítica (9.8) | 17% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request. | |
| Modificada | Media (6.1) | 0.71% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path. | |
| Modificada | Crítica (9.8) | 1.3% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password. | |
| Modificada | Alta (7.5) | 1.3% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information. | |
| Modificada | Crítica (9.8) | 20% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter. | |
| Modificada | Crítica (9.8) | 29% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter. | |
| Modificada | Media (6.1) | 0.71% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter. | |
| Modificada | Media (6.1) | 0.71% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information. | |
| Modificada | Alta (7.5) | 1.3% | — | Drobo 5N2 Firmware | 3/12/2018 | 17/6/2026 | Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via the "name" URL parameter. |