Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.12%—Acronis True ImageAIAcronis True Image FOR SandiskAIAcronis True Image FOR Western DigitalAIAcronis True Image OEMAI30/9/202517/6/2026
Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198, Acronis True Image for Western Digital (macOS) before build 42197, Acronis True Image OEM (macOS) before…
AplazadaAlta (7.3)0.18%—Acronis True ImageAIAcronis True Image FOR Western DigitalAIAcronis True Image FOR SandiskAIAcronis True Image OEMAI30/9/202517/6/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386, Acronis True Image for Western Digital (Windows) before build 42636, Acronis True Image for SanDisk (Windows) before build 42679, Acronis True Image OEM (Windows) before…
ModificadaCrítica (9.1)1.00%—Western Digital IBIWestern Digital MY Cloud Home20/2/202017/6/2026
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
ModificadaAlta (8.8)2.2%—Western Digital MY Cloud EX2 Ultra Firmware13/11/201917/6/2026
Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters.
ModificadaAlta (8.8)3.2%—Western Digital MY Cloud EX2 Ultra Firmware13/11/201917/6/2026
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.
ModificadaAlta (8.8)2.9%—Western Digital MY Cloud EX2 Ultra Firmware13/11/201917/6/2026
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow.
ModificadaCrítica (9.8)1.7%—Western Digital MY Cloud Mirror GEN 2 FirmwareWestern Digital MY Cloud EX2 Ultra FirmwareWestern Digital MY Cloud Ex2100 FirmwareWestern Digital MY Cloud Ex4100+524/4/201917/6/2026
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed…
ModificadaCrítica (9.8)87%—Western Digital MY Cloud Wdbctl0020hwt FirmwareWestern Digital MY Cloud Pr4100Western Digital MY Cloud Pr2100 FirmwareWestern Digital MY Cloud Mirror GEN 2 Firmware+818/9/201817/6/2026
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an…
ModificadaCrítica (9.8)98%—Western Digital Mycloud NAS3/1/201717/6/2026
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.
ModificadaCrítica (9.8)11%—Western Digital Mycloud NAS3/1/201717/6/2026
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
ModificadaAlta (10)79%—Western Digital Arkeia5/10/201517/6/2026
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.