Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.58% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and… | |
| Modificada | Media (6.1) | 0.76% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991… | |
| Modificada | Alta (8.1) | 1.6% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected… | |
| Modificada | Alta (8.8) | 1.7% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and… | |
| Modificada | Media (5.3) | 0.95% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 5/5/2022 | 17/6/2026 | A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of… | |
| Modificada | Media (6.1) | 0.64% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 7/1/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build… | |
| Modificada | Alta (7.2) | 1.9% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Alta (8.8) | 0.93% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Media (6.1) | 0.71% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 10/9/2021 | 17/6/2026 | A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630… | |
| Modificada | Media (5.4) | 0.51% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 3/6/2021 | 17/6/2026 | A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638… | |
| Modificada | Media (6.1) | 0.75% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 16/4/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build 20210202 (and later) QTS 4.5.1.1456 build… | |
| Modificada | Alta (7.5) | 0.67% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 31/12/2020 | 17/6/2026 | A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and… |