Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.58% | — | Qnap Qulog Center | 1/7/2021 | 17/6/2026 | A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QuLog Center versions prior to 1.2.0. | |
| Modificada | Media (6.1) | 0.58% | — | Qnap QTSQnap Quts Hero | 1/7/2021 | 17/6/2026 | An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build… | |
| Modificada | Crítica (9.8) | 1.4% | — | Qnap QTS | 24/6/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to… | |
| Modificada | Media (4.9) | 1.7% | — | Myqnapcloud Link | 16/6/2021 | 17/6/2026 | Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to… | |
| Modificada | Alta (8.8) | 1.2% | — | Qnap Helpdesk | 11/6/2021 | 17/6/2026 | An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4. | |
| Modificada | Media (5.5) | 0.24% | — | Qnap QSS | 11/6/2021 | 17/6/2026 | Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.3 build 20210505 on QSW-M2108-2C; versions prior to 1.0.3… | |
| Modificada | Alta (7.5) | 0.75% | — | Qnap QSS | 11/6/2021 | 17/6/2026 | An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read sensitive information on the system. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2C; versions prior to 1.0.2… | |
| Modificada | Alta (7.5) | 1.0% | — | Qnap Roon Server | 8/6/2021 | 17/6/2026 | If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later | |
| Modificada | Alta (8.8) | 1.6% | — | Qnap Video Station | 3/6/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2;… | |
| Modificada | Media (5.4) | 1.4% | — | Qnap Q'center | 3/6/2021 | 17/6/2026 | A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS… | |
| Modificada | Media (5.4) | 0.51% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 3/6/2021 | 17/6/2026 | A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638… | |
| Modificada | Alta (7.5) | 0.94% | — | Qnap QTSQnap Quts Hero | 21/5/2021 | 17/6/2026 | A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.2.1630 Build 20210406 and later QTS… | |
| Analizada | Crítica (9.8) | 78% | ⚠ Explotación activa💥 Exploit | Qnap Hybrid Backup Sync | 13/5/2021 | 17/6/2026 | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS… | |
| Modificada | Media (6.7) | 1.1% | — | Qnap Malware Remover | 13/5/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc.… | |
| Modificada | Alta (8.8) | 18% | — | Qnap Music Station | 13/5/2021 | 17/6/2026 | An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by gaining privileges, reading sensitive information, executing commands, evading detection, etc. This issue affects: QNAP… | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Media Streaming Add-onQnap Multimedia Console | 17/4/2021 | 17/6/2026 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the… | |
| Analizada | Crítica (9.8) | 34% | ⚠ Explotación activa💥 PoC | Qnap QTSQnap Quts Hero | 17/4/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build… | |
| Modificada | Media (6.1) | 0.75% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 16/4/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build 20210202 (and later) QTS 4.5.1.1456 build… | |
| Modificada | Crítica (9.8) | 5.9% | — | Qnap Surveillance Station | 14/4/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM… | |
| Modificada | Media (6.1) | 0.83% | — | Qnap Photo Station | 17/2/2021 | 17/6/2026 | This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later | |
| Modificada | Crítica (9.8) | 2.9% | — | Qnap Surveillance Station | 17/2/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM… | |
| Modificada | Crítica (9.8) | 3.0% | — | Qnap Helpdesk | 3/2/2021 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3. | |
| Analizada | Crítica (9.8) | 2.0% | ⚠ Explotación activa | Qnap Helpdesk | 3/2/2021 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to… | |
| Modificada | Alta (7.2) | 1.9% | — | Qnap QTSQnap Quts Hero | 11/1/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero… | |
| Modificada | Crítica (9.1) | 1.1% | — | Qnap QTS | 31/12/2020 | 17/6/2026 | A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following… |