Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.69% | — | Osnexus QuantastorAIInfluxdata KapacitorAI | 20/8/2026 | 1/9/2026 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Osnexus Quantastor SDS ManagerAI | 4/6/2026 | 22/7/2026 | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password. | |
| Analizada | Alta (8.7) | 0.52% | — | Quantatw Qoca AIM | 5/1/2026 | 30/9/2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (7.1) | 0.32% | — | Quantatw Qoca AIM | 5/1/2026 | 30/9/2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Alta (7.1) | 0.32% | — | Quantatw Qoca AIM | 5/1/2026 | 30/9/2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Media (5.3) | 0.36% | — | Quantatw Qoca AIM | 5/1/2026 | 30/9/2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability. | |
| Analizada | Media (5.3) | 0.36% | — | Quantatw Qoca AIM | 5/1/2026 | 30/9/2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability. | |
| Analizada | Alta (7.1) | 0.30% | — | Quantatw Qoca AIM | 5/1/2026 | 30/9/2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files. | |
| Aplazada | Alta (8.8) | 0.47% | — | Quanta Computer QocaAI | 31/12/2024 | 17/6/2026 | The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation. | |
| Modificada | Alta (7.2) | 0.96% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user. | |
| Modificada | Media (5.4) | 0.55% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user. | |
| Modificada | Alta (7.8) | 0.18% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`' | |
| Modificada | Alta (7.2) | 1.2% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC… | |
| Modificada | Alta (7.4) | 0.69% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)> | |
| Modificada | Media (4.9) | 0.69% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. POC Step 1: Prepare the SSRF with a request like this: GET… | |
| Modificada | Media (6.1) | 2.6% | — | Osnexus Quantastor | 28/8/2017 | 17/6/2026 | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript… | |
| Modificada | Media (5.3) | 4.7% | — | Osnexus Quantastor | 28/8/2017 | 17/6/2026 | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames. | |
| Modificada | Alta (7.5) | 3.0% | — | KDE QuantaConectiva LinuxGentoo LinuxKDE+2 | 22/4/2005 | 16/6/2026 | Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code. |