Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.38% | — | Qnap Quts HeroQnap QTS | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.36% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.1) | 0.38% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.45% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 0.47% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Analizada | Media (5.1) | 1.3% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build… | |
| Analizada | Media (6.9) | 0.56% | — | Qnap QTSQnap Quts Hero | 3/10/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Aplazada | Media (4.3) | 0.21% | — | Impaqtr AuroraAI | 1/10/2025 | 17/6/2026 | IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+37 | 24/9/2025 | 17/6/2026 | Memory corruption while encoding the image data. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+199 | 24/9/2025 | 17/6/2026 | Transient DOS while parsing the EPTM test control message to get the test pattern. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+25 | 24/9/2025 | 17/6/2026 | Memory corruption due to double free when multiple threads race to set the timestamp store. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+188 | 24/9/2025 | 17/6/2026 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency. | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 17/6/2026 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+245 | 24/9/2025 | 17/6/2026 | Memory corruption while performing private key encryption in trusted application. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 25/9/2026 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+169 | 24/9/2025 | 25/9/2026 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | |
| Analizada | Alta (7.1) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+283 | 24/9/2025 | 25/9/2026 | Cryptographic issue while performing RSA PKCS padding decoding. | |
| Analizada | Media (5.1) | 0.50% | — | Qnap QTSQnap Quts Hero | 29/8/2025 | 25/9/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QTS… |