Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.69% | — | Osnexus QuantastorAIInfluxdata KapacitorAI | 20/8/2026 | 1/9/2026 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Osnexus Quantastor SDS ManagerAI | 4/6/2026 | 22/7/2026 | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password. | |
| Modificada | Alta (7.2) | 0.96% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user. | |
| Modificada | Media (5.4) | 0.55% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user. | |
| Modificada | Alta (7.8) | 0.18% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`' | |
| Modificada | Alta (7.2) | 1.2% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC… | |
| Modificada | Alta (7.4) | 0.69% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)> | |
| Modificada | Media (4.9) | 0.69% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. POC Step 1: Prepare the SSRF with a request like this: GET… | |
| Modificada | Media (6.1) | 2.6% | — | Osnexus Quantastor | 28/8/2017 | 17/6/2026 | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript… | |
| Modificada | Media (5.3) | 4.7% | — | Osnexus Quantastor | 28/8/2017 | 17/6/2026 | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames. |