Base de datos CVE

325,000 vulnerabilidades indexadas

325,000+ resultados · página 1
Alto
CVE-2026-85410 CVSS 8.1 18 de sep. de 2026

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify the title and metadata of arbitrary WordPress posts or permanently delete arbitrary WordPress posts by supplying an attacker-controlled popup_id. The required nonce is emitted on the edit-jltma_popup admin screen, which is accessible to Contributors because the jltma_popup custom post type is registered with capability_type='post'.

Alto
CVE-2026-83561 CVSS 7.2 18 de sep. de 2026

The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie/script blocker enabled.

Alto
CVE-2026-6205 CVSS 8.1 18 de sep. de 2026

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.

Bajo
CVE-2026-56597 CVSS 3.1 18 de sep. de 2026

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.

Bajo
CVE-2026-56595 CVSS 3.1 18 de sep. de 2026

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.

Medio
CVE-2026-56592 CVSS 6.5 18 de sep. de 2026

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized system access.

Medio
CVE-2026-56590 CVSS 6.4 18 de sep. de 2026

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise.

Medio
CVE-2026-4036 CVSS 6.5 18 de sep. de 2026

An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.

Alto
CVE-2026-40539 CVSS 7.1 18 de sep. de 2026

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.

Bajo
CVE-2026-40538 CVSS 3.7 18 de sep. de 2026

An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.

Medio
CVE-2026-40537 CVSS 4.3 18 de sep. de 2026

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

Medio
CVE-2026-40536 CVSS 4.3 18 de sep. de 2026

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

Medio
CVE-2026-40535 CVSS 6.5 18 de sep. de 2026

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.

Medio
CVE-2026-40534 CVSS 5.4 18 de sep. de 2026

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.

Medio
CVE-2026-40533 CVSS 5.3 18 de sep. de 2026

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

Medio
CVE-2026-40532 CVSS 6.5 18 de sep. de 2026

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.

Medio
CVE-2026-40531 CVSS 4.3 18 de sep. de 2026

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.

Alto
CVE-2026-40530 CVSS 8.0 18 de sep. de 2026

An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.

Medio
CVE-2026-21848 CVSS 5.0 18 de sep. de 2026

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.

Medio
CVE-2026-21822 CVSS 6.3 18 de sep. de 2026

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification within the application's directory scope.

Crítico
CVE-2026-13684 CVSS 9.8 18 de sep. de 2026

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

Bajo
CVE-2026-13683 CVSS 2.7 18 de sep. de 2026

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.

Alto
CVE-2026-13673 CVSS 8.8 18 de sep. de 2026

An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks.

Bajo
CVE-2026-13666 CVSS 3.5 18 de sep. de 2026

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.

Crítico
CVE-2026-13639 CVSS 9.8 18 de sep. de 2026

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

¿Qué es la base de datos CVE?

La base de datos Common Vulnerabilities and Exposures (CVE) es el estándar global para identificar y rastrear vulnerabilidades de ciberseguridad conocidas públicamente. Cada entrada CVE contiene un identificador único, una puntuación de gravedad (CVSS), una descripción del fallo y referencias a parches o avisos de seguridad.

Cómo usar esta búsqueda CVE

Use el campo de búsqueda para encontrar vulnerabilidades por CVE ID (p. ej. CVE-2021-44228) o palabra clave. Filtre por nivel de gravedad — Crítico, Alto, Medio, Bajo — para priorizar parches. Use los filtros de año y puntuación CVSS para acotar los resultados relevantes.

Entender las puntuaciones CVSS

El Common Vulnerability Scoring System (CVSS) puntúa las vulnerabilidades de 0 a 10. Puntuaciones de 9,0–10,0 son Críticas y requieren acción inmediata. Puntuaciones de 7,0–8,9 son de gravedad Alta. Los administradores deben abordar primero las vulnerabilidades críticas y altas.

¿Quién debería usar esta base de datos?

Esta herramienta de referencia está diseñada para administradores de red, ingenieros de seguridad y profesionales de TI que necesitan evaluar la exposición al riesgo de dispositivos de red, routers, firewalls, cámaras y otros equipos. No está destinada para uso ofensivo.