Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.64% | — | Qnap QTSQnap Quts Hero | 16/12/2025 | 17/6/2026 | An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following… | |
| Analizada | Crítica (9.8) | 0.34% | — | Qnap Photo Station | 11/11/2025 | 17/6/2026 | Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research. | |
| Analizada | Baja (1.2) | 0.24% | — | Qnap Qulog Center | 7/11/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.927 ( 2025/09/17 ) and later | |
| Analizada | Baja (2.2) | 0.20% | — | Qnap Download Station | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Download Station… | |
| Analizada | Alta (7.8) | 0.49% | — | Qnap Qumagie | 7/11/2025 | 17/6/2026 | A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QuMagie 2.7.3 and later | |
| Analizada | Baja (2.3) | 0.47% | — | Qnap Download Station | 7/11/2025 | 17/6/2026 | A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Download Station… | |
| Analizada | Media (4) | 0.45% | — | Qnap Qsync Central | 7/11/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.3 ( 2025/08/28 )… | |
| Analizada | Baja (2.2) | 0.20% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018… | |
| Analizada | Baja (2.2) | 0.21% | — | Qnap Qulog Center | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuLog Center… | |
| Aplazada | Alta (7.2) | 0.50% | — | Qnap Notification CenterAI | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Media (4.9) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Baja (0.6) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later | |
| Analizada | Baja (1.2) | 0.48% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… | |
| Analizada | Media (4.9) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Media (4.9) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Baja (1.3) | 0.34% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later | |
| Analizada | Baja (1.3) | 0.34% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later | |
| Analizada | Crítica (9.5) | 0.39% | — | Qnap Qumagie | 7/11/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later | |
| Analizada | Media (5.3) | 0.34% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and… | |
| Analizada | Alta (8.5) | 0.21% | — | Qnap Netbak Replicator | 3/10/2025 | 17/6/2026 | An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: NetBak Replicator 4.5.15.0807 and… | |
| Analizada | Media (6.9) | 0.22% | — | Qnap Authenticator | 3/10/2025 | 17/6/2026 | An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later | |
| Analizada | Alta (8.6) | 0.42% | — | Qnap Qsync Central | 3/10/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later | |
| Analizada | Alta (8.6) | 0.42% | — | Qnap Qsync Central | 3/10/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later | |
| Analizada | Media (5.1) | 0.36% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.1) | 0.36% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following… |