Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.73% | — | Qnap Ragic Cloud DB | 20/11/2021 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic. | |
| Modificada | Alta (8.8) | 0.38% | — | Qnap Qmailagent | 20/11/2021 | 17/6/2026 | We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later | |
| Modificada | Crítica (9.8) | 1.3% | — | Qnap Multimedia Console | 13/11/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Multimedia Console: Multimedia Console 1.4.3 ( 2021/10/05 ) and later… | |
| Modificada | Media (6.1) | 0.71% | — | Qnap Qmailagent | 13/11/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later | |
| Modificada | Alta (7.2) | 1.3% | — | Qnap Media Streaming Add-on | 22/10/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming add-on: QTS 5.0.0: Media Streaming add-on… | |
| Modificada | Media (5.4) | 0.60% | — | Qnap Image2pdf | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Image2PDF: Image2PDF 2.1.5 ( 2021/08/17 ) and later | |
| Modificada | Media (5.4) | 0.65% | — | Qnap Photo Station | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later | |
| Modificada | Media (5.4) | 0.65% | — | Qnap Photo Station | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later… | |
| Modificada | Media (5.4) | 0.65% | — | Qnap Photo Station | 1/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later | |
| Modificada | Crítica (9.8) | 1.5% | — | Qnap QVR | 1/10/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210902 and later | |
| Modificada | Crítica (9.8) | 1.5% | — | Qnap QVR | 27/9/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later | |
| Modificada | Alta (7.2) | 1.5% | — | Qnap QVR | 27/9/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later | |
| Modificada | Crítica (9.8) | 1.5% | — | Qnap QVR | 27/9/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later | |
| Modificada | Crítica (9.8) | 1.6% | — | Qnap NVR Storage Expansion Firmware | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03… | |
| Modificada | Crítica (9.8) | 1.6% | — | Qnap Ej1600 FirmwareQnap Tl-r1620sdc FirmwareQnap Tl-r1620sep-rp FirmwareQnap Tl-r1220sep-rp Firmware+10 | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03… | |
| Modificada | Crítica (9.8) | 1.6% | — | Qnap Qusbcam2 | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 5.0:… | |
| Modificada | Alta (7.2) | 1.9% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Alta (8.8) | 0.93% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Alta (7.5) | 1.1% | — | Qnap Qsw-m2116p-2t2s FirmwareQnap Qunetswitch | 10/9/2021 | 17/6/2026 | A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this… | |
| Modificada | Media (6.1) | 0.71% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Crítica (9.8) | 1.5% | — | Qnap Viocard-30 FirmwareQnap Viocard-100 FirmwareQnap Viocard-300 FirmwareQnap Viogate-340a Firmware+1 | 9/8/2021 | 17/6/2026 | QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models | |
| Modificada | Crítica (9.8) | 16% | — | Qnap Hybrid Backup Sync | 8/7/2021 | 17/6/2026 | An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and… | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Quts Hero | 1/7/2021 | 17/6/2026 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions… | |
| Modificada | Media (5.4) | 0.47% | — | Qnap Q'center | 1/7/2021 | 17/6/2026 | This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004. | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Quts Hero | 1/7/2021 | 17/6/2026 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions… |