Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
333 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 34% | ⚠ Explotación activa💥 PoC | Qnap QTSQnap Quts Hero | 17/4/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build… | |
| Modificada | Media (6.1) | 0.75% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 16/4/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build 20210202 (and later) QTS 4.5.1.1456 build… | |
| Modificada | Alta (7.2) | 1.9% | — | Qnap QTSQnap Quts Hero | 11/1/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero… | |
| Modificada | Alta (7.5) | 0.67% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 31/12/2020 | 17/6/2026 | A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and… | |
| Modificada | Alta (8.8) | 2.6% | — | Qnap QTSQnap Quts Hero | 29/12/2020 | 17/6/2026 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. | |
| Modificada | Media (6.1) | 0.60% | — | Qnap Quts HeroQnap QTS | 10/12/2020 | 17/6/2026 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later… | |
| Modificada | Media (6.1) | 0.98% | — | Qnap Quts HeroQnap QTS | 10/12/2020 | 17/6/2026 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS… | |
| Modificada | Media (6.1) | 1.0% | — | Qnap Quts HeroQnap QTS | 10/12/2020 | 17/6/2026 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS… | |
| Modificada | Media (6.1) | 1.0% | — | Qnap Quts HeroQnap QTS | 10/12/2020 | 17/6/2026 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS… | |
| Modificada | Crítica (9.8) | 2.7% | — | Qnap Quts HeroQnap QTS | 10/12/2020 | 17/6/2026 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build… | |
| Modificada | Media (5.4) | 0.46% | — | Qualcomm Atheros Ar9132 FirmwareQualcomm Atheros Ar9283 FirmwareQualcomm Atheros Ar9285 Firmware | 30/9/2020 | 17/6/2026 | A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an… | |
| Modificada | Alta (8.1) | 0.46% | — | Pghero Project Pghero | 5/8/2020 | 17/6/2026 | The PgHero gem through 2.6.0 for Ruby allows CSRF. | |
| Modificada | Alta (7.5) | 3.2% | — | Cherokee-project Cherokee | 27/7/2020 | 17/6/2026 | Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within… | |
| Modificada | Alta (8.1) | 0.39% | — | Mids' Reborn Hero Designer Project Mids' Reborn Hero Designer | 11/6/2020 | 17/6/2026 | Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a man-in-the-middle attack against this connection and replace executable files with… | |
| Modificada | Alta (7.8) | 0.46% | — | Mids' Reborn Hero Designer Project Mids' Reborn Hero Designer | 11/6/2020 | 17/6/2026 | Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installation folder. Because of this, any user on the system can replace binaries or… | |
| Modificada | Crítica (9.8) | 2.1% | — | Cherokee-project Cherokee | 18/5/2020 | 17/6/2026 | In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers. | |
| Modificada | Alta (7.5) | 2.4% | — | Cherokee-project Cherokee | 18/5/2020 | 17/6/2026 | In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server. | |
| Modificada | Alta (8.4) | 1.7% | — | Cherokee-project Cherokee | 18/5/2020 | 17/6/2026 | An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary… | |
| Modificada | Crítica (9.8) | 4.8% | — | Apache Heron | 16/4/2020 | 17/6/2026 | It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data). | |
| Modificada | Crítica (9.8) | 2.8% | — | Heroku-addonpool Project Heroku-addonpool | 6/4/2020 | 17/6/2026 | heroku-addonpool through 0.1.15 is vulnerable to Command Injection. | |
| Modificada | Media (6.1) | 5.7% | 💥 Exploit | Heroplugins Hero Maps Premium | 26/2/2020 | 17/6/2026 | The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user… | |
| Modificada | Media (6.1) | 1.9% | — | Csshero | 4/12/2019 | 17/6/2026 | The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the… | |
| Modificada | Alta (7.5) | 1.3% | — | Cherokee-project Cherokee WEB Server | 22/7/2019 | 17/6/2026 | Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee command. The attack vector is: Overwrite argv[0] to an insane length with execl. The fixed version is: There's no fix yet. | |
| Modificada | Alta (7.5) | 6.9% | — | Apache Heron | 21/3/2019 | 17/6/2026 | When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd. | |
| Modificada | Alta (7.5) | 0.93% | — | Hashheroes | 26/12/2018 | 17/6/2026 | The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize… |