Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.5) | 0.83% | — | Qnap Qurouter | 6/12/2024 | 17/6/2026 | A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later | |
| Analizada | Crítica (9.5) | 2.3% | — | Qnap Hybrid Backup Sync | 6/12/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later | |
| Analizada | Crítica (10) | 10.0% | — | Qnap SMB Service | 6/12/2024 | 17/6/2026 | A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later | |
| Analizada | Alta (8.7) | 0.44% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Media (5.3) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Baja (2.3) | 0.42% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Alta (7.3) | 0.15% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Alta (7.7) | 1.1% | — | Qnap License Center | 6/12/2024 | 17/6/2026 | A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and later | |
| Analizada | Media (5.3) | 0.58% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Alta (7.7) | 0.65% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following… | |
| Analizada | Alta (7.7) | 0.63% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build… | |
| Analizada | Media (6.9) | 1.4% | 💥 PoC | Qnap Media Streaming Add-on | 22/11/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 )… | |
| Analizada | Alta (8.7) | 0.92% | — | Qnap Qulog Center | 22/11/2024 | 17/6/2026 | A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the vulnerability in the following versions: QuLog… | |
| Analizada | Alta (7.3) | 0.76% | — | Qnap Qurouter | 22/11/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later | |
| Analizada | Crítica (9.5) | 1.5% | — | Qnap Qurouter | 22/11/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later | |
| Analizada | Alta (7.9) | 0.65% | — | Qnap AI Core | 22/11/2024 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core 3.4.1 and later | |
| Analizada | Alta (8.4) | 0.18% | — | Qnap Notes Station 3 | 22/11/2024 | 17/6/2026 | An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following… | |
| Analizada | Crítica (9.4) | 0.62% | — | Qnap Notes Station 3 | 22/11/2024 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later | |
| Analizada | Alta (8.7) | 1.6% | — | Qnap Notes Station 3 | 22/11/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later | |
| Analizada | Crítica (9.3) | 0.93% | — | Qnap Notes Station 3 | 22/11/2024 | 17/6/2026 | A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later | |
| Analizada | Media (5.1) | 0.84% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS… |