Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
333 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.1% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters. | |
| Modificada | Crítica (9.8) | 1.1% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash). | |
| Modificada | Crítica (9.1) | 1.0% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories. | |
| Modificada | Alta (7.5) | 0.92% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location… | |
| Modificada | Crítica (9.8) | 2.2% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH. | |
| Modificada | Alta (7.5) | 1.3% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script | |
| Modificada | Media (6.5) | 0.79% | — | Secheron Sepcos Control AND Protection Relay Firmware | 24/6/2022 | 17/6/2026 | The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool. | |
| Modificada | Crítica (9.8) | 9.4% | 💥 Exploit | Memberhero Member Hero | 13/6/2022 | 17/6/2026 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments. | |
| Modificada | Media (6.1) | 0.58% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and… | |
| Modificada | Media (6.1) | 0.76% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991… | |
| Modificada | Alta (8.1) | 1.6% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected… | |
| Modificada | Alta (8.8) | 1.7% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and… | |
| Modificada | Media (5.3) | 0.95% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of… | |
| Modificada | Crítica (9.8) | 1.6% | — | Marketingheroes Sitesupercharger | 2/5/2022 | 17/6/2026 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections | |
| Modificada | Media (6.1) | 0.64% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 7/1/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build… | |
| Modificada | Crítica (9.8) | 0.82% | — | Huawei Hero-ct060 Firmware | 11/10/2021 | 17/6/2026 | There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful exploit could allow the attacker to do certain operations which the user are… | |
| Modificada | Alta (7.2) | 1.9% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Alta (8.8) | 0.93% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Media (6.1) | 0.71% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Alta (8.8) | 1.4% | — | Quantumcloud Slider Hero | 23/8/2021 | 17/6/2026 | The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection. | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Quts Hero | 1/7/2021 | 17/6/2026 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions… | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Quts Hero | 1/7/2021 | 17/6/2026 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions… | |
| Modificada | Media (6.1) | 0.58% | — | Qnap QTSQnap Quts Hero | 1/7/2021 | 17/6/2026 | An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build… | |
| Modificada | Media (5.4) | 0.51% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 3/6/2021 | 17/6/2026 | A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638… | |
| Modificada | Alta (7.5) | 0.94% | — | Qnap QTSQnap Quts Hero | 21/5/2021 | 17/6/2026 | A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.2.1630 Build 20210406 and later QTS… |