Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.13% | — | Qnap QcalagentAI | 18/9/2026 | 28/9/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later | |
| Modificada | Baja (1.3) | 0.56% | — | Qnap File Station | 10/6/2026 | 23/7/2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later | |
| Modificada | Baja (1.3) | 0.56% | — | Qnap File Station | 10/6/2026 | 23/7/2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later | |
| Modificada | Media (6.3) | 0.52% | — | Qnap File Station | 10/6/2026 | 23/7/2026 | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later | |
| Modificada | Media (6.6) | 0.48% | — | Qnap Qumagie | 10/6/2026 | 23/7/2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later | |
| Modificada | Media (6.2) | 0.34% | — | Qnap File Station | 10/6/2026 | 23/7/2026 | An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later | |
| Modificada | Baja (1.3) | 0.38% | — | Qnap File Station | 10/6/2026 | 23/7/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Modificada | Media (6.1) | 0.98% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build… | |
| Modificada | Baja (1.2) | 0.39% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS… | |
| Modificada | Baja (1.2) | 0.33% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS… | |
| Modificada | Baja (1.3) | 0.38% | — | Qnap File Station | 10/6/2026 | 23/7/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later | |
| Analizada | Alta (8.6) | 1.1% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Analizada | Media (6.9) | 0.46% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later… | |
| Analizada | Media (5.1) | 0.44% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following versions:… | |
| Analizada | Alta (8.6) | 1.1% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Analizada | Alta (8.6) | 1.1% | — | Qnap QTSQnap Quts Hero | 10/6/2026 | 23/7/2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Modificada | Media (4.6) | 0.26% | — | Qnap License Center | 10/6/2026 | 23/7/2026 | A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and… | |
| Analizada | Media (5.1) | 0.33% | — | Qnap Quts Hero | 10/6/2026 | 23/7/2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS… | |
| Analizada | Crítica (9.2) | 0.29% | — | Qnap QTS | 10/6/2026 | 23/7/2026 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later | |
| Analizada | Media (5.1) | 0.16% | — | Qnap Notification Center | 10/6/2026 | 5/8/2026 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later | |
| Analizada | Alta (8.7) | 0.61% | — | Qnap Qumagie | 9/6/2026 | 23/7/2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later | |
| Analizada | Media (5.1) | 0.45% | — | Qnap QTSQnap Quts Hero | 9/6/2026 | 23/7/2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build… | |
| Modificada | Media (6.3) | 0.33% | — | Qnap QTSQnap Quts Hero | 9/6/2026 | 23/7/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507… | |
| Modificada | Media (6.6) | 0.48% | — | Qnap Qumagie | 9/6/2026 | 23/7/2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later | |
| Analizada | Media (5.7) | 0.46% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later |