Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.52% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files. | |
| Pendiente de análisis | Alta (7.1) | 0.12% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.7) | 0.37% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks. | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | |
| Pendiente de análisis | Media (4.3) | 0.42% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks. | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched. | |
| Pendiente de análisis | Media (5.3) | 0.38% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information. | |
| Pendiente de análisis | Media (6.5) | 0.42% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information. | |
| Pendiente de análisis | Media (4.3) | 0.44% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks. | |
| Pendiente de análisis | Alta (8) | 0.49% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted. | |
| Pendiente de análisis | Crítica (9.8) | 0.60% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (2.7) | 0.32% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive… | |
| Pendiente de análisis | Alta (8.8) | 0.39% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.5) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL. | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information. | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files. | |
| En análisis | Media (6.5) | 0.27% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM. | |
| En análisis | Media (4.3) | 0.36% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. | |
| En análisis | Crítica (9) | 0.49% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM. | |
| Analizada | Alta (7.3) | 0.15% | — | Synology Assistant | 3/8/2026 | 21/8/2026 | An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation. | |
| Analizada | Media (4.3) | 0.28% | — | Synology Hyper Backup | 3/6/2026 | 22/7/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. | |
| Analizada | Media (4.1) | 0.30% | — | Synology Hyper Backup | 3/6/2026 | 22/7/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified… |