VYPR

Q'center

by QNAP Systems Inc.

CVEs (9)

  • CVE-2024-48862CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the…

  • CVE-2025-58469HigNov 7, 2025
    risk 0.57cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center…

  • CVE-2024-32762HigSep 6, 2024
    risk 0.53cvss 8.2epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuLog Center 1.8.0.872 ( 2024/06/17…

  • CVE-2023-23354HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed…

  • CVE-2020-36196MedJul 1, 2021
    risk 0.40cvss 6.1epss 0.01

    A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QuLog Center versions prior to 1.2.0.

  • CVE-2021-28803MedJul 1, 2021
    risk 0.35cvss 5.4epss 0.00

    This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.

  • CVE-2024-53696MedMar 7, 2025
    risk 0.32cvss 4.9epss 0.00

    A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following…

  • CVE-2025-54168MedNov 7, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in…

  • CVE-2023-23357MedDec 19, 2024
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data. We have…