VYPR

Vendor CVEs

Qnap

All CVEs

643 total · sorted by risk
  • CVE-2021-28812HigJun 3, 2021
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2;…

  • CVE-2021-28798HigMay 21, 2021
    risk 0.57cvss 8.8epss 0.01

    A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the following versions: QTS…

  • CVE-2020-25847HigDec 29, 2020
    risk 0.57cvss 8.8epss 0.03

    This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.

  • CVE-2017-7635HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.01

    QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.

  • CVE-2017-7641HigMar 8, 2018
    risk 0.57cvss 8.8epss 0.00

    QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.

  • CVE-2015-6022HigFeb 27, 2016
    risk 0.57cvss 8.8epss 0.03

    Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading an executable file, and then accessing this file via an unspecified URL.

  • CVE-2024-53694HigMar 7, 2025
    risk 0.56cvss epss 0.00

    A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already…

  • CVE-2025-44015HigAug 29, 2025
    risk 0.55cvss 8.4epss 0.01

    A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk…

  • CVE-2018-0707HigJul 17, 2018
    risk 0.55cvss 7.2epss 0.59

    Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.

  • CVE-2026-26239HigJun 10, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5…

  • CVE-2026-24724HigJun 10, 2026
    risk 0.53cvss 8.1epss 0.00

    An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have already fixed the vulnerability in the following version: File…

  • CVE-2025-57709HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.01

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-52870HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-52869HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-52868HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-48725HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-48724HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-48723HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central…

  • CVE-2025-30269HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the…

  • CVE-2025-59387HigJan 2, 2026
    risk 0.53cvss epss 0.00

    An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: MARS…

  • CVE-2025-52872HigJan 2, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-52864HigJan 2, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-52863HigJan 2, 2026
    risk 0.53cvss 8.1epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following…

  • CVE-2025-30273HigAug 29, 2025
    risk 0.53cvss 8.1epss 0.00

    An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following…

  • CVE-2025-47206HigAug 18, 2025
    risk 0.53cvss 8.1epss 0.00

    An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: File Station 5…

  • CVE-2025-22482HigJun 6, 2025
    risk 0.53cvss 8.1epss 0.00

    A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the…

  • CVE-2024-32762HigSep 6, 2024
    risk 0.53cvss 8.2epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuLog Center 1.8.0.872 ( 2024/06/17…

  • CVE-2023-23364HigSep 22, 2023
    risk 0.53cvss 8.1epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following…

  • CVE-2023-23363HigSep 22, 2023
    risk 0.53cvss 8.1epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions:…

  • CVE-2021-38692HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38691HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38690HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38689HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38682HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38687HigDec 29, 2021
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS…

  • CVE-2021-38684HigNov 13, 2021
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Multimedia Console:…

  • CVE-2021-28800HigJun 24, 2021
    risk 0.53cvss 8.1epss 0.01

    A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to…

  • CVE-2019-7181HigMay 9, 2019
    risk 0.53cvss 7.5epss 0.10

    Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.

  • CVE-2023-47564HigFeb 2, 2024
    risk 0.52cvss 8.0epss 0.01

    An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the…

  • CVE-2017-13068HigOct 6, 2017
    risk 0.52cvss 7.5epss 0.03

    QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.

  • CVE-2017-5227HigMar 23, 2017
    risk 0.52cvss 7.5epss 0.06

    QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.

  • CVE-2024-14026HigMar 11, 2026
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the…

  • CVE-2024-56808HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in…

  • CVE-2025-62842HigJan 2, 2026
    risk 0.51cvss 7.8epss 0.00

    An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the…

  • CVE-2025-57714HigOct 3, 2025
    risk 0.51cvss 7.8epss 0.00

    An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following…

  • CVE-2024-13088HigJun 6, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter…

  • CVE-2022-27595HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following…

  • CVE-2024-48861HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

  • CVE-2024-38642HigSep 6, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following…

  • CVE-2024-38641HigSep 6, 2024
    risk 0.51cvss 7.8epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors. We have already fixed the vulnerability in the following…

Page 4 of 13