VYPR

Vendor CVEs

Qnap

All CVEs

643 total · sorted by risk
  • CVE-2021-44055MedMay 5, 2022
    risk 0.35cvss 5.3epss 0.01

    An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability…

  • CVE-2021-38693MedMay 5, 2022
    risk 0.35cvss 5.3epss 0.01

    A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this…

  • CVE-2021-34361MedFeb 25, 2022
    risk 0.35cvss 5.3epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS…

  • CVE-2021-38677MedJan 14, 2022
    risk 0.35cvss 5.3epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent…

  • CVE-2021-38680MedDec 29, 2021
    risk 0.35cvss 5.3epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo…

  • CVE-2021-38681MedNov 20, 2021
    risk 0.35cvss 5.3epss 0.01

    A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center,…

  • CVE-2021-38675MedOct 1, 2021
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Image2PDF: Image2PDF…

  • CVE-2021-28803MedJul 1, 2021
    risk 0.35cvss 5.4epss 0.00

    This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.

  • CVE-2017-7639MedJun 5, 2018
    risk 0.35cvss 5.3epss 0.01

    QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.

  • CVE-2017-7630MedMar 27, 2018
    risk 0.35cvss 5.3epss 0.01

    QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.

  • CVE-2024-13086MedMar 7, 2025
    risk 0.34cvss 5.3epss 0.00

    An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build…

  • CVE-2024-48866MedDec 6, 2024
    risk 0.34cvss 5.3epss 0.00

    An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in…

  • CVE-2023-39303MedFeb 2, 2024
    risk 0.34cvss 5.3epss 0.00

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-23371MedOct 6, 2023
    risk 0.34cvss 5.2epss 0.00

    A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. We have already fixed the vulnerability…

  • CVE-2021-34360MedMay 26, 2022
    risk 0.34cvss 5.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server:…

  • CVE-2025-58468MedJun 10, 2026
    risk 0.33cvss epss 0.00

    A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version:…

  • CVE-2023-50362MedApr 26, 2024
    risk 0.33cvss 5.0epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-50361MedApr 26, 2024
    risk 0.33cvss 5.0epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-32967MedFeb 2, 2024
    risk 0.33cvss 5.0epss 0.00

    An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have…

  • CVE-2025-66274MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-59386MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-58472MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following…

  • CVE-2025-58471MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

  • CVE-2025-58466MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected…

  • CVE-2025-57711MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

  • CVE-2025-57710MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

  • CVE-2025-54163MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following…

  • CVE-2025-54162MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the…

  • CVE-2025-54161MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

  • CVE-2025-54155MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

  • CVE-2025-47205MedFeb 11, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-59381MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the…

  • CVE-2025-59380MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.01

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the…

  • CVE-2025-57705MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or…

  • CVE-2025-54166MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following…

  • CVE-2025-54165MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following…

  • CVE-2025-54164MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following…

  • CVE-2025-53596MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-53590MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-53589MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-53414MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-53405MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-52431MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-52430MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-52426MedJan 2, 2026
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-58463MedNov 7, 2025
    risk 0.32cvss 4.9epss 0.00

    A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in…

  • CVE-2025-53411MedNov 7, 2025
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

  • CVE-2025-52866MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-52862MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-52860MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…