Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.98% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build… | |
| Modificada | Baja (1.2) | 0.39% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Modificada | Baja (1.2) | 0.33% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Alta (8.6) | 1.1% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Analizada | Media (6.9) | 0.46% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later… | |
| Analizada | Media (5.1) | 0.44% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Alta (8.6) | 1.1% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Analizada | Alta (8.6) | 1.1% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Analizada | Crítica (9.2) | 0.29% | — | Qnap QTS | 10/6/2026 | 23/7/2026 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later | |
| Analizada | Media (5.1) | 0.45% | — | Qnap QTSQnap Quts Hero | 9/6/2026 | 23/7/2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Modificada | Media (6.3) | 0.33% | — | Qnap QTSQnap Quts Hero | 9/6/2026 | 23/7/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507… | |
| Analizada | Media (6.7) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+46 | 1/6/2026 | 22/7/2026 | Memory corruption in diagnostic services due to absence of input validation | |
| Aplazada | Crítica (9.3) | 0.17% | — | Pcmanfm QTAI | 22/5/2026 | 23/7/2026 | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code… | |
| Pendiente de análisis | Baja (1.8) | 0.09% | — | QtbaseAIOpensslAI | 19/5/2026 | 29/7/2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory. | |
| Aplazada | Alta (7.5) | 0.28% | — | Justdoit0910 TinymqttAI | 18/5/2026 | 17/6/2026 | In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length Client ID while CleanSession is set to 0, the broker correctly replies with a CONNACK return code 0x02 (Identifier… | |
| Analizada | Alta (8.7) | 0.68% | — | Freertos Coremqtt | 15/5/2026 | 17/6/2026 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. | |
| Aplazada | Alta (8.4) | 0.19% | — | StigqterAI | 14/5/2026 | 17/6/2026 | STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly run the "Export HTML"… | |
| Pendiente de análisis | Alta (8.7) | 0.47% | — | QT SVGAI | 6/5/2026 | 29/7/2026 | A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A non-marker element (such as a <line> element) that… | |
| Modificada | Alta (7.4) | 0.22% | — | Qtdeclarative | 30/4/2026 | 30/9/2026 | Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information… | |
| Aplazada | Media (5.1) | 0.30% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and HTM file uploads. Authenticated attackers can upload HTML files containing arbitrary JavaScript through the image upload or… | |
| Aplazada | Media (5.1) | 0.32% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only detecting specific patterns while returning unsanitized strings without output encoding. Attackers can inject malicious… | |
| Aplazada | Alta (7.1) | 0.79% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the… | |
| Aplazada | Alta (7.1) | 0.54% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access controls by directly… | |
| Aplazada | Alta (8.7) | 1.6% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit… | |
| Aplazada | Crítica (9.3) | 0.66% | 💥 PoC | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the… |