Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.52% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files. | |
| Pendiente de análisis | Alta (7.1) | 0.12% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.7) | 0.37% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks. | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | |
| Pendiente de análisis | Media (4.3) | 0.42% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks. | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched. | |
| Pendiente de análisis | Media (5.3) | 0.38% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information. | |
| Pendiente de análisis | Media (6.5) | 0.42% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information. | |
| Pendiente de análisis | Media (4.3) | 0.44% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks. | |
| Pendiente de análisis | Alta (8) | 0.49% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted. | |
| Pendiente de análisis | Crítica (9.8) | 0.60% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (2.7) | 0.32% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive… | |
| Pendiente de análisis | Alta (8.8) | 0.39% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.5) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL. | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information. | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files. | |
| Analizada | Crítica (9.8) | 0.53% | — | Synology Diskstation Manager | 27/5/2026 | 30/9/2026 | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). | |
| Analizada | Alta (8.8) | 0.38% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via… | |
| Analizada | Alta (7.5) | 0.48% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors. | |
| Analizada | Crítica (9.6) | 0.37% | — | Synology Diskstation ManagerSynology Diskstation Manager Unified Controller | 4/12/2025 | 26/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Alta (7.5) | 0.53% | — | Synology Diskstation Manager | 23/4/2025 | 17/6/2026 | Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Analizada | Media (5.3) | 32% | — | Synology Beestation OSSynology Diskstation Manager | 19/3/2025 | 17/6/2026 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors. |