Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)38%💥 PoCQnap QTSQnap Quts Hero21/5/202417/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS…
ModificadaAlta (8.8)0.69%—Qnap QTSQnap Quts Hero21/5/202417/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520…
ModificadaAlta (8.8)0.69%—Qnap QTSQnap Quts Hero21/5/202417/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520…
ModificadaAlta (8.8)0.70%—Qnap QTSQnap Quts Hero21/5/202417/6/2026
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute arbitrary code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero…
ModificadaAlta (8.1)0.35%—Qnap QTSQnap Quts Hero21/5/202417/6/2026
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following version: QTS…
ModificadaCrítica (9.8)0.97%—QTFedoraproject Fedora18/5/202417/6/2026
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
AplazadaMedia (6)0.50%—Opupi0 Amqp MqttAI14/5/202417/6/2026
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.
AnalizadaAlta (7.5)0.32%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+1806/5/202417/6/2026
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
AnalizadaAlta (7.8)0.13%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+446/5/202417/6/2026
Memory corruption when the channel ID passed by user is not validated and further used.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2326/5/202417/6/2026
Memory corruption when the payload received from firmware is not as per the expected protocol size.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1546/5/202417/6/2026
Memory corruption in HLOS while checking for the storage type.
AnalizadaAlta (7.5)0.32%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+1576/5/202417/6/2026
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
AnalizadaAlta (7)0.08%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1576/5/202417/6/2026
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
AnalizadaCrítica (10)2.3%—Qnap QTSQnap Quts HeroQnap Qutscloud26/4/202417/6/2026
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build…
AnalizadaAlta (7.5)1.4%—Qnap QTSQnap Quts HeroQnap Qutscloud26/4/202417/6/2026
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build…
AnalizadaAlta (8.2)0.46%—Qnap QTSQnap Quts HeroQnap Qutscloud26/4/202417/6/2026
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110…
AnalizadaAlta (7.5)35%—Qnap QTSQnap Quts HeroQnap Qutscloud26/4/202417/6/2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build…
AnalizadaAlta (7.5)40%—Qnap QTSQnap Quts HeroQnap Qutscloud26/4/202417/6/2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build…
ModificadaAlta (8.8)0.85%—Qnap QTSQnap Quts Hero26/4/202417/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402…
ModificadaAlta (8.1)0.42%—Qnap QTSQnap Quts Hero26/4/202417/6/2026
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build…
ModificadaAlta (8.8)0.76%—Qnap QTSQnap Quts Hero26/4/202417/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402…
ModificadaAlta (8.8)0.76%—Qnap QTSQnap Quts Hero26/4/202417/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402…
AplazadaCrítica (9.8)0.68%—MqttAI9/4/202417/6/2026
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
AnalizadaAlta (8.8)1.2%—Projeqtor4/4/202417/6/2026
projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.
AnalizadaMedia (5.4)0.39%—Projeqtor4/4/202417/6/2026
projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.