Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
–

333 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.34%—MemberheroAI29/8/20263/9/2026
The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving…
AplazadaAlta (8.8)0.51%—Slider Hero With Video Background AnimationAI22/8/202626/8/2026
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an…
AplazadaMedia (4.9)0.48%—Quantumcloud Slider HeroAI16/8/202620/8/2026
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image…
ModificadaMedia (6.1)0.98%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build…
ModificadaBaja (1.2)0.39%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS…
ModificadaBaja (1.2)0.33%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS…
AnalizadaAlta (8.6)1.1%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build…
AnalizadaMedia (6.9)0.46%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later…
AnalizadaMedia (5.1)0.44%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following versions:…
AnalizadaAlta (8.6)1.1%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build…
AnalizadaAlta (8.6)1.1%—Qnap QTSQnap Quts Hero10/6/202623/7/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build…
AnalizadaMedia (5.1)0.33%—Qnap Quts Hero10/6/202623/7/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS…
AnalizadaMedia (5.1)0.45%—Qnap QTSQnap Quts Hero9/6/202623/7/2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build…
ModificadaMedia (6.3)0.33%—Qnap QTSQnap Quts Hero9/6/202623/7/2026
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507…
AnalizadaAlta (7.4)0.29%—Schemahero30/3/202617/6/2026
SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go.
AnalizadaAlta (7.4)0.29%—Schemahero30/3/202617/6/2026
SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins/postgres/lib/column.go.
AnalizadaBaja (2)0.62%—Qnap QTSQnap Quts Hero11/3/202617/6/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions:…
AnalizadaCrítica (9.2)0.67%—Qnap QTSQnap Quts Hero11/2/202617/6/2026
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS…
ModificadaMedia (5.1)0.39%—Qnap Quts Hero11/2/202617/6/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS…
AnalizadaBaja (1.2)0.39%—Qnap Quts Hero11/2/202617/6/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS…
AnalizadaBaja (1.2)0.53%—Qnap QTSQnap Quts Hero11/2/202617/6/2026
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways. We have already fixed the…
AnalizadaBaja (0.6)0.42%—Qnap QTSQnap Quts Hero11/2/202617/6/2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build…
AnalizadaMedia (5.1)0.44%—Qnap QTSQnap Quts Hero11/2/202617/6/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS…
AplazadaAlta (8.5)0.19%—Atheros Coex Service ApplicationAI27/1/202617/6/2026
Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.
ModificadaAlta (7.5)0.51%—Heromotocorp Vida V1 PRO Firmware9/1/202617/6/2026
An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component