Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.32% | — | Qnap Media Streaming Add-on | 20/3/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later | |
| Analizada | Baja (2) | 0.60% | — | Qnap Media Streaming Add-on | 11/2/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: Media Streaming… | |
| Analizada | Baja (1.7) | 0.11% | — | Qnap Media Streaming Add-on | 11/2/2026 | 17/6/2026 | An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later | |
| Analizada | Media (6.9) | 1.4% | 💥 PoC | Qnap Media Streaming Add-on | 22/11/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 )… | |
| Analizada | Media (6.6) | 1.2% | — | Qnap Media Streaming Add-on | 3/5/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and… | |
| Analizada | Crítica (9.8) | 0.54% | — | Qnap Media Streaming Add-on | 26/4/2024 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 (… | |
| Modificada | Crítica (9.8) | 15% | — | Qnap QTSQnap Multimedia ConsoleQnap Media Streaming Add-on | 3/11/2023 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia… | |
| Modificada | Alta (7.2) | 1.3% | — | Qnap Media Streaming Add-on | 22/10/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming add-on: QTS 5.0.0: Media Streaming add-on… | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Media Streaming Add-onQnap Multimedia Console | 17/4/2021 | 17/6/2026 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the… | |
| Modificada | Alta (8.8) | 0.45% | — | Qnap Media Streaming Add-on | 8/3/2018 | 17/6/2026 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections. | |
| Modificada | Crítica (9.8) | 3.1% | — | Qnap Media Streaming Add-on | 8/3/2018 | 17/6/2026 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges. | |
| Modificada | Media (6.5) | 0.67% | — | Qnap Media Streaming Add-on | 8/3/2018 | 17/6/2026 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS. | |
| Modificada | Media (6.1) | 0.76% | — | Qnap Media Streaming Add-on | 8/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page. |