Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.44% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Media (5.3) | 0.48% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Baja (2.3) | 0.42% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954… | |
| Analizada | Alta (7.3) | 0.15% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.3) | 0.58% | — | Qnap QTSQnap Quts Hero | 6/12/2024 | 17/6/2026 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Baja (2.1) | 0.59% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the… | |
| Analizada | Alta (7.7) | 0.65% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following… | |
| Analizada | Alta (7.7) | 0.63% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build… | |
| Analizada | Media (5.1) | 0.84% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.84% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.63% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Media (5.1) | 0.84% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Baja (2.1) | 0.69% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data. We have already fixed the vulnerability in the… | |
| Analizada | Media (5.1) | 0.60% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Media (5.1) | 0.85% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.69% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data. We have already fixed the vulnerability in the… | |
| Analizada | Media (5.1) | 0.60% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Media (5.1) | 0.85% | — | Qnap QTSQnap Quts Hero | 22/11/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Alta (7.3) | 0.54% | — | Qnap QTSQnap Quts Hero | 6/9/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and… | |
| Analizada | Baja (2.4) | 0.20% | — | Qnap QTSQnap Quts Hero | 6/9/2024 | 17/6/2026 | An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors.… | |
| Analizada | Media (5.3) | 0.58% | — | Qnap QTSQnap Quts Hero | 6/9/2024 | 17/6/2026 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712… | |
| Analizada | Media (4.7) | 0.81% | — | Qnap QTSQnap Quts Hero | 6/9/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and… |