Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.5%—Qsan Storage Manager7/7/202117/6/2026
Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
ModificadaCrítica (9.8)1.4%—Qsan SanosQsan Storage ManagerQsan Xevo7/7/202117/6/2026
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
ModificadaCrítica (9.8)0.71%—Qsan SanosQsan Storage ManagerQsan Xevo7/7/202117/6/2026
Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
ModificadaCrítica (9.8)1.0%—Qsan Storage Manager7/7/202117/6/2026
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
ModificadaAlta (7.5)0.85%—Qsan SanosQsan Storage ManagerQsan Xevo7/7/202117/6/2026
Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.2, QSAN XEVO v2.1.0,…
ModificadaAlta (7.5)1.7%—Qsan Storage Manager7/7/202117/6/2026
A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaAlta (7.5)1.3%—Qsan Storage Manager7/7/202117/6/2026
Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular parameter in download function. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaAlta (7.5)1.7%—Qsan Storage Manager7/7/202117/6/2026
Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (5.3)0.79%—Qsan Storage Manager7/7/202117/6/2026
Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and further access credential information. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaAlta (7.5)1.2%—Qsan Storage Manager7/7/202117/6/2026
Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaCrítica (9.8)2.1%—Qsan Storage Manager7/7/202117/6/2026
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaCrítica (9.8)2.1%—Qsan Storage Manager7/7/202117/6/2026
QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (4.3)0.85%—Qsan Storage Manager7/7/202117/6/2026
QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (4.3)0.85%—Qsan Storage Manager7/7/202117/6/2026
QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (6.5)1.3%—Qsan Storage Manager7/7/202117/6/2026
Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (6.5)1.3%—Qsan Storage Manager7/7/202117/6/2026
Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (6.5)1.3%—Qsan Storage Manager7/7/202117/6/2026
Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
ModificadaMedia (6.5)1.3%—Qsan Storage Manager7/7/202117/6/2026
Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3 .
ModificadaAlta (7.5)3.3%—Python Urllib3Fedoraproject FedoraOracle Enterprise Manager OPS CenterOracle Instantis Enterprisetrack+129/6/202117/6/2026
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
ModificadaAlta (7.5)51%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+215/6/202117/6/2026
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was…
ModificadaAlta (8.1)60%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+2211/6/202117/6/2026
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at…
ModificadaMedia (5.3)3.0%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+1811/6/202117/6/2026
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if…
ModificadaMedia (5.3)53%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+210/6/202117/6/2026
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
ModificadaCrítica (9.8)68%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+410/6/202117/6/2026
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
ModificadaAlta (7.5)65%💥 PoCApache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+210/6/202117/6/2026
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service