Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.95% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analizada | Media (6.8) | 0.32% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analizada | Crítica (9.3) | 0.68% | — | Qnap QVR PRO | 20/3/2026 | 17/6/2026 | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later | |
| Analizada | Alta (8.1) | 1.1% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later | |
| Modificada | Media (6.2) | 0.18% | — | Qnap Quftp | 20/3/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service… | |
| Analizada | Alta (7.3) | 0.20% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later | |
| Analizada | Media (5.6) | 0.18% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to cause unexpected behavior. We have already fixed the vulnerability in the following version: QuRouter… | |
| Analizada | Media (4) | 0.20% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later | |
| Analizada | Baja (0.9) | 0.28% | — | Qnap Qurouter | 20/3/2026 | 17/6/2026 | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.7) | 0.32% | — | Qnap Media Streaming Add-on | 20/3/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later | |
| Analizada | Media (6.6) | 0.47% | — | Qnap Hyper Data Protector | 12/3/2026 | 17/6/2026 | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later | |
| Analizada | Baja (2) | 0.62% | — | Qnap QTSQnap Quts Hero | 11/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Baja (0.1) | 0.14% | — | Qnap Video Station | 11/3/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video… | |
| Analizada | Baja (0.1) | 0.08% | — | Qnap Video Station | 11/3/2026 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following… | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 )… | |
| Analizada | Baja (1.3) | 0.44% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later | |
| Analizada | Crítica (9.2) | 0.67% | — | Qnap QTSQnap Quts Hero | 11/2/2026 | 17/6/2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS… | |
| Modificada | Media (5.1) | 0.39% | — | Qnap Quts Hero | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Baja (1.3) | 0.35% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and… | |
| Analizada | Baja (1.3) | 0.36% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and… | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and… | |
| Analizada | Media (5.2) | 0.64% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later | |
| Analizada | Baja (1.2) | 0.39% | — | Qnap Quts Hero | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS… | |
| Analizada | Baja (1.2) | 0.59% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… |