Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.12% | — | Synology Active Backup FOR Business Recovery Media Creator | 3/6/2026 | 22/7/2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Active Backup FOR Business Agent | 27/5/2026 | 7/10/2026 | An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Alta (8.6) | 0.37% | — | Synology Active Backup FOR Business | 27/5/2026 | 7/10/2026 | A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. | |
| Analizada | Baja (2.7) | 0.48% | — | Synology Active Backup FOR Business Agent | 13/2/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing… | |
| Analizada | Media (6.5) | 0.40% | — | Synology Active Backup FOR Business Agent | 13/2/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors. | |
| Analizada | Media (6.5) | 0.57% | — | Synology Active Backup FOR Business Agent | 13/2/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified… | |
| Analizada | Media (5.3) | 0.08% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors. | |
| Analizada | Media (5.5) | 0.18% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors. | |
| Analizada | Media (5) | 0.08% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors. | |
| Analizada | Baja (3.3) | 0.16% | — | Synology Active Backup FOR Business Agent | 26/9/2024 | 17/6/2026 | Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout. |