Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.55%—Netgear Readynas OS Firmware29/4/202017/6/2026
NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.
ModificadaMedia (6.7)0.57%—Netgear Readynas OS Firmware29/4/202017/6/2026
NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.
ModificadaMedia (4.9)1.0%—Netgear Readynas OS27/4/202017/6/2026
NETGEAR ReadyNAS devices before 6.9.3 are affected by incorrect configuration of security settings.
ModificadaAlta (8.8)0.74%—Netgear Readynas OS23/4/202017/6/2026
NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.
ModificadaAlta (8.8)0.58%—Netgear Readynas OS Firmware23/4/202017/6/2026
NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.
ModificadaMedia (4.8)0.60%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.2)0.32%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings.
ModificadaMedia (4.8)0.58%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.48%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaBaja (3.3)0.33%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings.
ModificadaMedia (4.8)0.48%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.48%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.48%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.60%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.62%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.48%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (4.8)0.58%—Netgear Readynas OS21/4/202017/6/2026
NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
ModificadaMedia (6.1)0.83%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.
ModificadaMedia (5.4)0.64%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
ModificadaMedia (6.1)0.80%—Seagate NAS OS13/5/201917/6/2026
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
ModificadaAlta (7.5)1.4%—Seagate NAS OS13/5/201917/6/2026
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
ModificadaMedia (6.1)3.1%—Seagate NAS OS13/5/201917/6/2026
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
ModificadaMedia (5.4)0.64%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
ModificadaAlta (7.5)1.7%—Seagate NAS OS13/5/201917/6/2026
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
ModificadaMedia (6.1)0.69%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.