Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)10%—Zspace Q2C NAS Firmware5/12/202525/9/2026
A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument safe_dir causes command injection. It is possible to initiate the attack remotely.…
ModificadaAlta (7.4)12%—Zspace Q2C NAS Firmware5/12/202525/9/2026
A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation of the argument safe_dir results in command injection. The attack may be performed…
ModificadaAlta (7.4)12%—Zspace Q2C NAS Firmware5/12/202525/9/2026
A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir leads to command injection. The attack is possible to be carried out remotely. The…
AnalizadaMedia (6.5)0.49%—Iptime NAS Firmware30/7/202517/6/2026
A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking.…
AnalizadaMedia (6.5)0.30%—Ixsystems Truenas Firmware30/12/202417/6/2026
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this…
AnalizadaAlta (8.8)1.6%—Ixsystems Truenas Firmware30/12/202417/6/2026
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this vulnerability. The specific flaw…
ModificadaAlta (7.8)1.1%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller+126/2/202117/6/2026
Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.
ModificadaCrítica (9)1.5%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic.
ModificadaMedia (5.9)0.74%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.
ModificadaAlta (8.7)0.67%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session.
ModificadaMedia (6.7)0.51%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.
ModificadaAlta (8.1)1.9%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header.
ModificadaAlta (8.1)2.1%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header.
ModificadaAlta (7.4)0.77%—Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller26/2/202117/6/2026
Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session.
AnalizadaAlta (7.8)100%⚠ Explotación activaSudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+2026/1/202117/6/2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
ModificadaAlta (8.3)0.83%—Synology Diskstation ManagerSynology Skynas Firmware29/10/202017/6/2026
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
ModificadaBaja (3.7)0.56%—Synology Diskstation ManagerSynology Skynas Firmware29/10/202017/6/2026
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
ModificadaCrítica (9)0.72%—Synology Diskstation ManagerSynology Skynas Firmware29/10/202017/6/2026
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (8.8)0.63%—Netgear D8500 FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6000 Firmware+2627/4/202017/6/2026
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.42, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.24, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150 before 1.0.0.42, EX6200 before…
ModificadaAlta (8.8)0.46%—Netgear R7300 FirmwareNetgear R8500 FirmwareNetgear Dgn2200 FirmwareNetgear D2200d Firmware+120/4/202017/6/2026
Certain NETGEAR devices are affected by CSRF. This affects R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200DW-1FRNAS before 1.0.0.32.
ModificadaAlta (7.5)3.0%—Ixsystems Freenas FirmwareIxsystems Truenas Firmware8/4/202017/6/2026
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.
ModificadaAlta (8.8)0.64%—Neetcables Airstream NAS Firmware8/8/201917/6/2026
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
ModificadaMedia (6.5)0.52%—Neetcables Airstream NAS Firmware7/8/201917/6/2026
Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
ModificadaMedia (6.1)0.55%—SambaFedoraproject FedoraSynology Directory ServerSynology Router Manager+39/4/201917/6/2026
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded…
ModificadaCrítica (9.8)44%—Seagate Business NAS Firmware8/6/201717/6/2026
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.