Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Drobo 5N2 Firmware24/2/202017/6/2026
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications, but also poses…
ModificadaCrítica (9.8)1.9%—Drobo 5N2 Firmware3/12/201817/6/2026
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.
ModificadaCrítica (9.8)1.3%—Drobo 5N2 Firmware3/12/201817/6/2026
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
ModificadaAlta (7.5)28%—Drobo 5N2 Firmware3/12/201817/6/2026
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.
ModificadaCrítica (9.8)17%—Drobo 5N2 Firmware3/12/201817/6/2026
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request.
ModificadaMedia (6.1)0.71%—Drobo 5N2 Firmware3/12/201817/6/2026
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.
ModificadaCrítica (9.8)1.3%—Drobo 5N2 Firmware3/12/201817/6/2026
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.
ModificadaAlta (7.5)1.3%—Drobo 5N2 Firmware3/12/201817/6/2026
Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.
ModificadaCrítica (9.8)20%—Drobo 5N2 Firmware3/12/201817/6/2026
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.
ModificadaAlta (7.5)1.3%—Drobo 5N2 Firmware3/12/201817/6/2026
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.
ModificadaCrítica (9.8)29%—Drobo 5N2 Firmware3/12/201817/6/2026
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.
ModificadaMedia (6.1)0.71%—Drobo 5N2 Firmware3/12/201817/6/2026
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.
ModificadaMedia (6.1)0.71%—Drobo 5N2 Firmware3/12/201817/6/2026
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.
ModificadaAlta (7.5)1.3%—Drobo 5N2 Firmware3/12/201817/6/2026
Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.
ModificadaAlta (7.5)1.3%—Drobo 5N2 Firmware3/12/201817/6/2026
Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via the "name" URL parameter.