Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

333 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.57%—Kpherox Pleroma15/10/202317/6/2026
A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emoji.Pack of the file lib/pleroma/emoji/pack.ex. The manipulation of the argument name leads to path traversal. The complexity of an attack is rather high. The exploitability is told to be difficult.…
ModificadaAlta (7.5)0.61%—Qnap QTSQnap Quts HeroQnap Qutscloud13/10/202317/6/2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.0.2444 build…
ModificadaAlta (7.2)0.55%—Qnap QTSQnap Quts HeroQnap Qutscloud13/10/202317/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build…
ModificadaMedia (4.9)0.50%—Qnap QTSQnap Quts HeroQnap Qutscloud13/10/202317/6/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. QES is not affected. We have already fixed the vulnerability in the following…
ModificadaAlta (7.2)0.59%—Qnap QTSQnap Quts HeroQnap Qutscloud6/10/202317/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build…
ModificadaAlta (7.2)0.59%—Qnap QTSQnap Quts HeroQnap Qutscloud6/10/202317/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build…
ModificadaAlta (8.8)1.6%—Qnap QTSQnap Quts HeroQnap Qutscloud22/9/202317/6/2026
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS…
ModificadaMedia (5.3)0.48%—Qnap QTSQnap Quts Hero24/8/202317/6/2026
An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444…
ModificadaMedia (6.5)0.17%—Qnap QTSQnap Quts Hero24/8/202317/6/2026
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors. We have already fixed the vulnerability in the following…
ModificadaAlta (8.8)0.10%—Qnap QTSQnap Quts Hero24/8/202317/6/2026
An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS…
ModificadaMedia (4.3)0.39%—Quantumcloud Slider Hero12/7/202317/6/2026
The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request…
ModificadaAlta (8.8)0.79%💥 PoCHeroelectronix Qubo Hcd01 FirmwareHeroelectronix Qubo Hcd02 Firmware4/7/202317/6/2026
Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.
ModificadaMedia (6.1)0.38%—Cththemes Theroof26/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions.
ModificadaMedia (5.4)0.36%—Essentialplugin Hero Banner Ultimate4/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.
ModificadaBaja (2.7)0.66%—Qnap QTSQnap Quts HeroQnap QutscloudQnap Qvp-41b Firmware+629/3/202317/6/2026
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already…
ModificadaBaja (2.7)0.66%—Qnap QVRQnap QTSQnap Quts HeroQnap Qutscloud+729/3/202317/6/2026
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already…
ModificadaAlta (7.2)1.2%—Qnap QVRQnap QTSQnap Quts HeroQnap Qutscloud+729/3/202317/6/2026
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors. QES is not affected. We have already fixed the vulnerability in the following versions: QTS…
ModificadaCrítica (9.8)2.7%—Qnap QTSQnap Quts Hero30/1/202317/6/2026
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build…
ModificadaAlta (7.5)0.83%—Pghero Project Pghero5/1/202317/6/2026
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)
ModificadaCrítica (9.2)0.78%—Heidenhain TNC 640 Programming StationHeidenhain Heros28/10/202217/6/2026
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on the production line, steal sensitive data…
ModificadaCrítica (9.8)1.6%—Apache Heron24/10/202217/6/2026
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
ModificadaMedia (4.8)0.59%—Quantumcloud Slider Hero26/9/202217/6/2026
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
ModificadaCrítica (9.8)1.3%—Heroku-env Project Heroku-env2/8/202217/6/2026
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
ModificadaCrítica (9.8)1.6%—Heroiclabs Nakama5/7/202217/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.
ModificadaAlta (7.5)0.88%—Heroiclabs Nakama5/7/202217/6/2026
Old session tokens can be used to authenticate to the application and send authenticated requests.
Orbitaley — Vulnerabilidades