Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.9)0.61%—Westerndigital WD DiscoveryAI26/1/202617/6/2026
DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path.
AplazadaCrítica (9.3)1.1%—Westerndigital MY CloudAI29/9/202517/6/2026
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
AplazadaAlta (8.4)0.17%—Westerndigital KitfoxAI22/8/202517/6/2026
Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with the SYSTEM privilege.
AplazadaCrítica (9.2)0.47%—Westerndigital MY CloudAI27/9/202417/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.
AplazadaAlta (7.1)0.26%—NodejsAIElectronAIWesterndigital WD DiscoveryAI2/8/202417/6/2026
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution…
AplazadaMedia (5.9)0.32%—Sandisk IBIAIWesterndigital MY CloudAIWesterndigital MY Cloud HomeAIWesterndigital WD CloudAI24/6/202417/6/2026
A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious…
ModificadaMedia (4.9)0.82%—Westerndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Mirror G2 Firmware+85/2/202417/6/2026
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My…
ModificadaMedia (5.5)0.24%—Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+95/2/202417/6/2026
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that…
ModificadaAlta (7.8)0.25%—Westerndigital Sandisk Security Installer15/11/202317/6/2026
Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges…
ModificadaCrítica (9.8)0.69%—Westerndigital MY Cloud OS1/7/202317/6/2026
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
ModificadaAlta (8.8)0.87%—Westerndigital MY Cloud OS30/6/202317/6/2026
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.
ModificadaMedia (6.7)1.3%—Westerndigital MY Cloud OS30/6/202317/6/2026
Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over the network and the attacker must already have admin/root privileges to…
ModificadaAlta (7.5)0.59%—Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+812/6/202317/6/2026
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102;…
ModificadaMedia (4.9)0.77%—Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware18/5/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo,…
ModificadaCrítica (9.8)1.5%—Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware18/5/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western…
ModificadaMedia (4.9)0.57%—Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware18/5/202317/6/2026
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My…
ModificadaMedia (5.5)0.14%—Westerndigital MY Cloud OS10/5/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud…
ModificadaCrítica (9.8)1.4%—Westerndigital MY Cloud OS10/5/202317/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution…
ModificadaCrítica (9.8)1.8%—Westerndigital MY Cloud OS10/5/202317/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
ModificadaAlta (7.5)0.30%—Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware10/5/202317/6/2026
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
ModificadaAlta (8.1)0.56%—Westerndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home Firmware10/5/202317/6/2026
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to…
ModificadaMedia (4.3)0.46%—Westerndigital MY CloudWesterndigital MY Cloud HomeWesterndigital MY Cloud OS 5Westerndigital Sandisk IBI8/5/202317/6/2026
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing…
ModificadaAlta (7.4)0.31%—Westerndigital Sandisk Privateaccess24/3/202317/6/2026
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
ModificadaCrítica (9.8)0.81%—Westerndigital MY Cloud OS6/2/202317/6/2026
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
ModificadaAlta (8.8)1.0%—Westerndigital MY Cloud OS6/2/202317/6/2026
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
Orbitaley — Vulnerabilidades