Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 38% | 💥 PoC | Qnap QTSQnap Quts Hero | 21/5/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS… | |
| Modificada | Alta (8.8) | 0.69% | — | Qnap QTSQnap Quts Hero | 21/5/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520… | |
| Modificada | Alta (8.8) | 0.69% | — | Qnap QTSQnap Quts Hero | 21/5/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520… | |
| Modificada | Alta (8.8) | 0.70% | — | Qnap QTSQnap Quts Hero | 21/5/2024 | 17/6/2026 | A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute arbitrary code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero… | |
| Modificada | Alta (8.1) | 0.35% | — | Qnap QTSQnap Quts Hero | 21/5/2024 | 17/6/2026 | An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following version: QTS… | |
| Modificada | Crítica (9.8) | 0.97% | — | QTFedoraproject Fedora | 18/5/2024 | 17/6/2026 | QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values. | |
| Aplazada | Media (6) | 0.50% | — | Opupi0 Amqp MqttAI | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+180 | 6/5/2024 | 17/6/2026 | Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+44 | 6/5/2024 | 17/6/2026 | Memory corruption when the channel ID passed by user is not validated and further used. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+232 | 6/5/2024 | 17/6/2026 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+154 | 6/5/2024 | 17/6/2026 | Memory corruption in HLOS while checking for the storage type. | |
| Analizada | Alta (7.5) | 0.32% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+157 | 6/5/2024 | 17/6/2026 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | |
| Analizada | Alta (7) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+157 | 6/5/2024 | 17/6/2026 | Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache. | |
| Analizada | Crítica (10) | 2.3% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 26/4/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build… | |
| Analizada | Alta (7.5) | 1.4% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 26/4/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build… | |
| Analizada | Alta (8.2) | 0.46% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 26/4/2024 | 17/6/2026 | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110… | |
| Analizada | Alta (7.5) | 35% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 26/4/2024 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build… | |
| Analizada | Alta (7.5) | 40% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 26/4/2024 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build… | |
| Modificada | Alta (8.8) | 0.85% | — | Qnap QTSQnap Quts Hero | 26/4/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402… | |
| Modificada | Alta (8.1) | 0.42% | — | Qnap QTSQnap Quts Hero | 26/4/2024 | 17/6/2026 | An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build… | |
| Modificada | Alta (8.8) | 0.76% | — | Qnap QTSQnap Quts Hero | 26/4/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402… | |
| Modificada | Alta (8.8) | 0.76% | — | Qnap QTSQnap Quts Hero | 26/4/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402… | |
| Aplazada | Crítica (9.8) | 0.68% | — | MqttAI | 9/4/2024 | 17/6/2026 | An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates. | |
| Analizada | Alta (8.8) | 1.2% | — | Projeqtor | 4/4/2024 | 17/6/2026 | projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php. | |
| Analizada | Media (5.4) | 0.39% | — | Projeqtor | 4/4/2024 | 17/6/2026 | projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php. |