Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.38% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and… | |
| Analizada | Media (5.1) | 0.31% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138… | |
| Analizada | Media (5.3) | 0.49% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.3) | 0.49% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.3) | 0.37% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145… | |
| Analizada | Media (5.3) | 0.37% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145… | |
| Analizada | Baja (2.3) | 0.38% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526… | |
| Analizada | Alta (7.7) | 0.91% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and… | |
| Analizada | Media (5.3) | 0.46% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145… | |
| Analizada | Alta (8.7) | 0.95% | — | Qnap QTSQnap Quts Hero | 6/6/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321… | |
| Analizada | Media (5.3) | 0.42% | — | Qnap QTSQnap Quts Hero | 6/6/2025 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build… | |
| Analizada | Baja (2.1) | 0.50% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build… | |
| Analizada | Baja (2.1) | 0.39% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later… | |
| Analizada | Baja (2.1) | 0.50% | — | Qnap Quts HeroQnap QTS | 7/3/2025 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build… | |
| Analizada | Media (5.1) | 0.45% | — | Qnap Qulog CenterQnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01… | |
| Analizada | Alta (7.1) | 0.49% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.1) | 0.83% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build… | |
| Analizada | Media (5.1) | 0.41% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.50% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixed the vulnerability in… | |
| Analizada | Alta (7.5) | 0.42% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later QuTS hero h5.2.0.2851… | |
| Analizada | Alta (7.5) | 0.59% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 19/12/2024 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2277 and later QTS… | |
| Analizada | Alta (8.7) | 23% | 💥 PoC | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Baja (2.1) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.53% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Alta (8.7) | 1.3% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950… |