VYPR

Vendor CVEs

Qnap

All CVEs

643 total · sorted by risk
  • CVE-2023-41287MedJan 5, 2024
    risk 0.28cvss 4.3epss 0.01

    A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later

  • CVE-2023-39301MedNov 3, 2023
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network. We have already fixed the vulnerability in the…

  • CVE-2021-44054MedMay 5, 2022
    risk 0.28cvss 4.3epss 0.01

    An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following…

  • CVE-2018-19947MedSep 11, 2020
    risk 0.28cvss 4.3epss 0.01

    The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

  • CVE-2024-32765MedAug 12, 2024
    risk 0.27cvss 4.2epss 0.00

    A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following…

  • CVE-2023-41290MedApr 26, 2024
    risk 0.27cvss 4.1epss 0.00

    A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the…

  • CVE-2021-38674MedJan 7, 2022
    risk 0.27cvss 4.2epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and…

  • CVE-2018-19946MedSep 11, 2020
    risk 0.27cvss 4.2epss 0.00

    The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already…

  • CVE-2023-45037LowFeb 2, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45036LowFeb 2, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45035LowFeb 2, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-41292LowFeb 2, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45044LowJan 5, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45043LowJan 5, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45042LowJan 5, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45041LowJan 5, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45040LowJan 5, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-45039LowJan 5, 2024
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-32973LowOct 13, 2023
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-32972LowOct 6, 2023
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-32971LowOct 6, 2023
    risk 0.25cvss 3.8epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2024-27125LowSep 6, 2024
    risk 0.23cvss 3.5epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and…

  • CVE-2023-47219LowJan 5, 2024
    risk 0.23cvss 3.5epss 0.01

    A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

  • CVE-2023-34972LowAug 24, 2023
    risk 0.23cvss 3.5epss 0.00

    A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors. We have already…

  • CVE-2023-50359LowFeb 2, 2024
    risk 0.22cvss 3.4epss 0.00

    An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated administrators to place the system in a state that could lead to a crash or other unintended behaviors via…

  • CVE-2025-62840LowJan 2, 2026
    risk 0.21cvss 3.3epss 0.00

    A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the…

  • CVE-2023-34973LowAug 24, 2023
    risk 0.20cvss 3.1epss 0.00

    An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425…

  • CVE-2021-28801LowJun 11, 2021
    risk 0.20cvss 3.1epss 0.01

    An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read sensitive information on the system. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on…

  • CVE-2022-27598LowMar 29, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP…

  • CVE-2022-27597LowMar 29, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP…

  • CVE-2024-32771LowSep 6, 2024
    risk 0.17cvss 2.6epss 0.00

    An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication…

  • CVE-2020-2505LowDec 24, 2020
    risk 0.15cvss 2.3epss 0.00

    If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

  • CVE-2018-19948LowSep 11, 2020
    risk 0.13cvss 2.0epss 0.00

    The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue…

  • CVE-2013-0143Jun 7, 2013
    risk 0.04cvss epss 0.07

    cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

  • CVE-2007-1543Mar 20, 2007
    risk 0.01cvss epss 0.08

    Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a long path slave name in a USL socket connection.

  • CVE-2015-6003Oct 16, 2015
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

  • CVE-2014-5457Aug 25, 2014
    risk 0.00cvss epss 0.00

    QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.

  • CVE-2013-5760Jun 9, 2014
    risk 0.00cvss epss 0.01

    QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.

  • CVE-2013-7174Jan 9, 2014
    risk 0.00cvss epss 0.02

    Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname in the f parameter.

  • CVE-2013-0144Jun 7, 2013
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.

  • CVE-2013-0142Jun 7, 2013
    risk 0.00cvss epss 0.01

    QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

  • CVE-2009-3279Sep 21, 2009
    risk 0.00cvss epss 0.00

    The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.

  • CVE-2009-3200Sep 21, 2009
    risk 0.00cvss epss 0.00

    The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this…

Page 13 of 13