Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.69%—Osnexus QuantastorAIInfluxdata KapacitorAI20/8/20261/9/2026
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of…
Pendiente de análisisCrítica (9.8)0.44%—Osnexus Quantastor SDS ManagerAI4/6/202622/7/2026
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.
AnalizadaAlta (8.7)0.52%—Quantatw Qoca AIM5/1/202630/9/2026
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (7.1)0.32%—Quantatw Qoca AIM5/1/202630/9/2026
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
AnalizadaAlta (7.1)0.32%—Quantatw Qoca AIM5/1/202630/9/2026
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
AnalizadaMedia (5.3)0.36%—Quantatw Qoca AIM5/1/202630/9/2026
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.
AnalizadaMedia (5.3)0.36%—Quantatw Qoca AIM5/1/202630/9/2026
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.
AnalizadaAlta (7.1)0.30%—Quantatw Qoca AIM5/1/202630/9/2026
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files.
AplazadaAlta (8.8)0.47%—Quanta Computer QocaAI31/12/202417/6/2026
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.
ModificadaAlta (7.2)0.96%—Osnexus Quantastor10/7/202317/6/2026
An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user.
ModificadaMedia (5.4)0.55%—Osnexus Quantastor10/7/202317/6/2026
An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user.
ModificadaAlta (7.8)0.18%—Osnexus Quantastor10/7/202317/6/2026
Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`'
ModificadaAlta (7.2)1.2%—Osnexus Quantastor10/7/202317/6/2026
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC…
ModificadaAlta (7.4)0.69%—Osnexus Quantastor10/7/202317/6/2026
An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)>
ModificadaMedia (4.9)0.69%—Osnexus Quantastor10/7/202317/6/2026
An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. POC Step 1: Prepare the SSRF with a request like this: GET…
ModificadaMedia (6.1)2.6%—Osnexus Quantastor28/8/201717/6/2026
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript…
ModificadaMedia (5.3)4.7%—Osnexus Quantastor28/8/201717/6/2026
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.
ModificadaAlta (7.5)3.0%—KDE QuantaConectiva LinuxGentoo LinuxKDE+222/4/200516/6/2026
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.