VYPR

Notes Station 3

by Qnap

CVEs (6)

  • CVE-2024-38643CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following…

  • CVE-2024-38644HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

  • CVE-2024-38645MedNov 22, 2024
    risk 0.42cvss 6.5epss 0.01

    A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3…

  • CVE-2024-27126MedSep 6, 2024
    risk 0.41cvss 6.3epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3…

  • CVE-2024-27122MedSep 6, 2024
    risk 0.41cvss 6.3epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3…

  • CVE-2024-38646MedNov 22, 2024
    risk 0.39cvss 6.0epss 0.00

    An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already…