VYPR

QTS

by QNAP Systems Inc.

CVEs (211)

  • CVE-2023-41276MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-41275MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-41274MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. We have already fixed the…

  • CVE-2023-41273MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2018-0719MedNov 27, 2018
    risk 0.36cvss 5.5epss 0.01

    Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4…

  • CVE-2024-56805MedJun 6, 2025
    risk 0.35cvss 5.4epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the…

  • CVE-2023-51368MedSep 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-51367MedSep 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2024-13086MedMar 7, 2025
    risk 0.34cvss 5.3epss 0.00

    An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build…

  • CVE-2024-48866MedDec 6, 2024
    risk 0.34cvss 5.3epss 0.00

    An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in…

  • CVE-2023-39303MedFeb 2, 2024
    risk 0.34cvss 5.3epss 0.00

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-50362MedApr 26, 2024
    risk 0.33cvss 5.0epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-50361MedApr 26, 2024
    risk 0.33cvss 5.0epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-32967MedFeb 2, 2024
    risk 0.33cvss 5.0epss 0.00

    An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have…

  • CVE-2025-58466MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected…

  • CVE-2025-47205MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-59381MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the…

  • CVE-2025-59380MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.01

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the…

  • CVE-2025-57705MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or…

  • CVE-2025-54166MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following…

Page 7 of 11