Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

333 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)1.1%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.
ModificadaCrítica (9.8)1.1%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).
ModificadaCrítica (9.1)1.0%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.
ModificadaAlta (7.5)0.92%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location…
ModificadaCrítica (9.8)2.2%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.
ModificadaAlta (7.5)1.3%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script
ModificadaMedia (6.5)0.79%—Secheron Sepcos Control AND Protection Relay Firmware24/6/202217/6/2026
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.
ModificadaCrítica (9.8)9.4%💥 ExploitMemberhero Member Hero13/6/202217/6/2026
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
ModificadaMedia (6.1)0.58%—Qnap QTSQnap Quts HeroQnap Qutscloud5/5/202217/6/2026
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and…
ModificadaMedia (6.1)0.76%—Qnap QTSQnap Quts HeroQnap Qutscloud5/5/202217/6/2026
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991…
ModificadaAlta (8.1)1.6%—Qnap QTSQnap Quts HeroQnap Qutscloud5/5/202217/6/2026
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected…
ModificadaAlta (8.8)1.7%—Qnap QTSQnap Quts HeroQnap Qutscloud5/5/202217/6/2026
A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and…
ModificadaMedia (5.3)0.95%—Qnap QTSQnap Quts HeroQnap Qutscloud5/5/202217/6/2026
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of…
ModificadaCrítica (9.8)1.6%—Marketingheroes Sitesupercharger2/5/202217/6/2026
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
ModificadaMedia (6.1)0.64%—Qnap QTSQnap Quts HeroQnap Qutscloud7/1/202217/6/2026
A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build…
ModificadaCrítica (9.8)0.82%—Huawei Hero-ct060 Firmware11/10/202117/6/2026
There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful exploit could allow the attacker to do certain operations which the user are…
ModificadaAlta (7.2)1.9%—Qnap QTSQnap Quts HeroQnap Qutscloud10/9/202117/6/2026
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630…
ModificadaAlta (8.8)0.93%—Qnap QTSQnap Quts HeroQnap Qutscloud10/9/202117/6/2026
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630…
ModificadaMedia (6.1)0.71%—Qnap QTSQnap Quts HeroQnap Qutscloud10/9/202117/6/2026
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630…
ModificadaAlta (8.8)1.4%—Quantumcloud Slider Hero23/8/202117/6/2026
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.
ModificadaCrítica (9.8)1.8%—Qnap QTSQnap Quts Hero1/7/202117/6/2026
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions…
ModificadaCrítica (9.8)1.8%—Qnap QTSQnap Quts Hero1/7/202117/6/2026
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions…
ModificadaMedia (6.1)0.58%—Qnap QTSQnap Quts Hero1/7/202117/6/2026
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build…
ModificadaMedia (5.4)0.51%—Qnap QTSQnap Quts HeroQnap Qutscloud3/6/202117/6/2026
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638…
ModificadaAlta (7.5)0.94%—Qnap QTSQnap Quts Hero21/5/202117/6/2026
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.2.1630 Build 20210406 and later QTS…
Orbitaley — Vulnerabilidades