Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.55% | — | Netgear Readynas OS Firmware | 29/4/2020 | 17/6/2026 | NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection. | |
| Modificada | Media (6.7) | 0.57% | — | Netgear Readynas OS Firmware | 29/4/2020 | 17/6/2026 | NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection. | |
| Modificada | Media (4.9) | 1.0% | — | Netgear Readynas OS | 27/4/2020 | 17/6/2026 | NETGEAR ReadyNAS devices before 6.9.3 are affected by incorrect configuration of security settings. | |
| Modificada | Alta (8.8) | 0.74% | — | Netgear Readynas OS | 23/4/2020 | 17/6/2026 | NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF. | |
| Modificada | Alta (8.8) | 0.58% | — | Netgear Readynas OS Firmware | 23/4/2020 | 17/6/2026 | NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF. | |
| Modificada | Media (4.8) | 0.60% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.2) | 0.32% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings. | |
| Modificada | Media (4.8) | 0.58% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.48% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Baja (3.3) | 0.33% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings. | |
| Modificada | Media (4.8) | 0.48% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.48% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.48% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.60% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.62% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.48% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (4.8) | 0.58% | — | Netgear Readynas OS | 21/4/2020 | 17/6/2026 | NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | |
| Modificada | Media (6.1) | 0.83% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL. | |
| Modificada | Media (5.4) | 0.64% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names. | |
| Modificada | Media (6.1) | 0.80% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting. | |
| Modificada | Alta (7.5) | 1.4% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost. | |
| Modificada | Media (6.1) | 3.1% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names. | |
| Modificada | Alta (7.5) | 1.7% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path. | |
| Modificada | Media (6.1) | 0.69% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names. |