Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
333 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.50% | — | Qnap Quts HeroQnap QTS | 7/3/2025 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build… | |
| Analizada | Media (5.1) | 0.45% | — | Qnap Qulog CenterQnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01… | |
| Analizada | Alta (7.1) | 0.49% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.1) | 0.83% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build… | |
| Analizada | Media (5.1) | 0.41% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.50% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixed the vulnerability in… | |
| Analizada | Alta (7.5) | 0.42% | — | Qnap QTSQnap Quts Hero | 7/3/2025 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later QuTS hero h5.2.0.2851… | |
| Analizada | Media (6.5) | 0.35% | — | Heroplugins Hero Maps Premium | 7/3/2025 | 17/6/2026 | The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.35% | — | Hero SliderAI | 5/3/2025 | 17/6/2026 | The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.34% | — | Hero Mega MenuAI | 5/3/2025 | 17/6/2026 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the hmenu_delete_menu() function in all versions up to, and including, 1.16.5. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Media (6.1) | 0.26% | — | Hero Mega MenuAI | 5/3/2025 | 17/6/2026 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'index' parameter in all versions up to, and including, 1.16.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.35% | — | Hero Mega MenuAI | 5/3/2025 | 17/6/2026 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several functions in all versions up to, and including, 1.16.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (4.3) | 0.34% | — | Gohero Store CustomizerAI | 25/1/2025 | 17/6/2026 | The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend() function in all versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to update limited… | |
| Aplazada | Alta (8.5) | 0.37% | — | Notfound Hero Mega MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Alta (8.5) | 0.37% | — | Notfound Hero Mega Menu - Responsive Wordpress MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Alta (7.1) | 0.28% | — | Notfoundhero Hero Mega MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows Reflected XSS. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Media (6.5) | 0.56% | — | Essentialplugin Hero Banner UltimateAI | 7/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugin Hero Banner Ultimate hero-banner-ultimate allows PHP Local File Inclusion.This issue affects Hero Banner Ultimate: from n/a through <= 1.4.4. | |
| Analizada | Alta (7.5) | 0.59% | — | Qnap QTSQnap Quts HeroQnap Qutscloud | 19/12/2024 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2277 and later QTS… | |
| Analizada | Alta (8.7) | 23% | 💥 PoC | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Baja (2.1) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.53% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Alta (8.7) | 1.3% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950… | |
| Analizada | Alta (8.7) | 0.44% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Media (5.3) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Baja (2.3) | 0.42% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… |