Qnap
Qnap Qumagie: vulnerabilidades y CVE
Qnap Qumagie tiene 13 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-26237 | Media (6.6) | 0.48% | — | 10 jun 2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the… |
| CVE-2026-44083 | Alta (8.7) | 0.61% | — | 9 jun 2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the… |
| CVE-2026-26236 | Media (6.6) | 0.48% | — | 9 jun 2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the… |
| CVE-2025-62857 | Baja (2.2) | 0.22% | — | 2 ene 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the… |
| CVE-2025-58464 | Alta (7.8) | 0.49% | — | 7 nov 2025 | A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed… |
| CVE-2025-52425 | Crítica (9.5) | 0.39% | — | 7 nov 2025 | An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following… |
| CVE-2024-38642 | Baja (1) | 0.10% | — | 6 sept 2024 | An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We… |
| CVE-2023-47560 | Alta (8.8) | 1.1% | — | 5 ene 2024 | An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in… |
| CVE-2023-47559 | Media (5.4) | 0.30% | — | 5 ene 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the… |
| CVE-2023-47219 | Alta (8.8) | 0.50% | — | 5 ene 2024 | A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the… |
| CVE-2023-41285 | Alta (8.8) | 0.54% | — | 10 nov 2023 | A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the… |
| CVE-2023-41284 | Alta (8.8) | 0.54% | — | 10 nov 2023 | A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the… |
| CVE-2023-39295 | Alta (8.8) | 1.7% | — | 10 nov 2023 | An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.