Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 110 Firmware | 23/2/2018 | 17/6/2026 | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php. | |
| Modificada | Crítica (9.8) | 2.7% | — | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 110 Firmware | 23/2/2018 | 17/6/2026 | backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Seagate Blackarmor NAS 220 Firmware | 11/10/2017 | 17/6/2026 | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php. | |
| Modificada | Media (6.8) | 1.4% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 220 | 21/1/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3)… | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 220 | 9/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php. | |
| Modificada | Alta (10) | 4.4% | — | Seagate Blackarmor NAS | 25/5/2012 | 16/6/2026 | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors. |