Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 10% | — | Zspace Q2C NAS Firmware | 5/12/2025 | 25/9/2026 | A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument safe_dir causes command injection. It is possible to initiate the attack remotely.… | |
| Modificada | Alta (7.4) | 12% | — | Zspace Q2C NAS Firmware | 5/12/2025 | 25/9/2026 | A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation of the argument safe_dir results in command injection. The attack may be performed… | |
| Modificada | Alta (7.4) | 12% | — | Zspace Q2C NAS Firmware | 5/12/2025 | 25/9/2026 | A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir leads to command injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Media (6.5) | 0.49% | — | Iptime NAS Firmware | 30/7/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking.… | |
| Analizada | Media (6.5) | 0.30% | — | Ixsystems Truenas Firmware | 30/12/2024 | 17/6/2026 | iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 1.6% | — | Ixsystems Truenas Firmware | 30/12/2024 | 17/6/2026 | iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Modificada | Alta (7.8) | 1.1% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller+1 | 26/2/2021 | 17/6/2026 | Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options. | |
| Modificada | Crítica (9) | 1.5% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic. | |
| Modificada | Media (5.9) | 0.74% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session. | |
| Modificada | Alta (8.7) | 0.67% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. | |
| Modificada | Media (6.7) | 0.51% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.9% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. | |
| Modificada | Alta (8.1) | 2.1% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. | |
| Modificada | Alta (7.4) | 0.77% | — | Synology Diskstation ManagerSynology Vs960hd FirmwareSynology Skynas FirmwareSynology Diskstation Manager Unified Controller | 26/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Alta (8.3) | 0.83% | — | Synology Diskstation ManagerSynology Skynas Firmware | 29/10/2020 | 17/6/2026 | Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. | |
| Modificada | Baja (3.7) | 0.56% | — | Synology Diskstation ManagerSynology Skynas Firmware | 29/10/2020 | 17/6/2026 | Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. | |
| Modificada | Crítica (9) | 0.72% | — | Synology Diskstation ManagerSynology Skynas Firmware | 29/10/2020 | 17/6/2026 | Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (8.8) | 0.63% | — | Netgear D8500 FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6000 Firmware+26 | 27/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.42, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.24, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150 before 1.0.0.42, EX6200 before… | |
| Modificada | Alta (8.8) | 0.46% | — | Netgear R7300 FirmwareNetgear R8500 FirmwareNetgear Dgn2200 FirmwareNetgear D2200d Firmware+1 | 20/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by CSRF. This affects R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200DW-1FRNAS before 1.0.0.32. | |
| Modificada | Alta (7.5) | 3.0% | — | Ixsystems Freenas FirmwareIxsystems Truenas Firmware | 8/4/2020 | 17/6/2026 | An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent. | |
| Modificada | Alta (8.8) | 0.64% | — | Neetcables Airstream NAS Firmware | 8/8/2019 | 17/6/2026 | Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page. | |
| Modificada | Media (6.5) | 0.52% | — | Neetcables Airstream NAS Firmware | 7/8/2019 | 17/6/2026 | Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password. | |
| Modificada | Media (6.1) | 0.55% | — | SambaFedoraproject FedoraSynology Directory ServerSynology Router Manager+3 | 9/4/2019 | 17/6/2026 | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded… | |
| Modificada | Crítica (9.8) | 44% | — | Seagate Business NAS Firmware | 8/6/2017 | 17/6/2026 | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens. |