VYPR

Vendor CVEs

Qnap

All CVEs

643 total · sorted by risk
  • CVE-2023-39298HigSep 6, 2024
    risk 0.51cvss 7.8epss 0.00

    A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access data or perform actions that they should not be allowed to perform via unspecified vectors.…

  • CVE-2021-28805HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.3 build 20210505 on…

  • CVE-2019-7201HigDec 4, 2019
    risk 0.51cvss 7.8epss 0.00

    An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges. QNAP have already fixed this…

  • CVE-2017-13070HigDec 11, 2017
    risk 0.51cvss 7.8epss 0.02

    A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.

  • CVE-2024-27130HigMay 21, 2024
    risk 0.50cvss 7.2epss 0.38

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS…

  • CVE-2023-23366HigOct 6, 2023
    risk 0.50cvss 7.7epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-23365HigOct 6, 2023
    risk 0.50cvss 7.7epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following…

  • CVE-2021-28807HigJun 3, 2021
    risk 0.50cvss 7.7epss 0.01

    A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS…

  • CVE-2018-0721HigNov 27, 2018
    risk 0.50cvss 7.7epss 0.02

    Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build…

  • CVE-2026-26237HigJun 10, 2026
    risk 0.49cvss 7.5epss 0.00

    A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and…

  • CVE-2026-26236HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and…

  • CVE-2025-57713HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.01

    A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

  • CVE-2025-9110HigJan 2, 2026
    risk 0.49cvss 7.5epss 0.00

    An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have already fixed the…

  • CVE-2025-59384HigJan 2, 2026
    risk 0.49cvss 7.5epss 0.00

    A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qfiling 3.13.1 and later

  • CVE-2025-62848HigDec 16, 2025
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions:…

  • CVE-2025-62847HigDec 16, 2025
    risk 0.49cvss 7.5epss 0.01

    An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic. We have already fixed the vulnerability in the…

  • CVE-2025-58464HigNov 7, 2025
    risk 0.49cvss 7.5epss 0.00

    A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QuMagie 2.7.3…

  • CVE-2025-29877HigJun 6, 2025
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-29876HigJun 6, 2025
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-29873HigJun 6, 2025
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-29872HigJun 6, 2025
    risk 0.49cvss 7.5epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type…

  • CVE-2025-22490HigJun 6, 2025
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2024-48868HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in…

  • CVE-2024-48867HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.01

    An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in…

  • CVE-2024-48865HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability…

  • CVE-2024-38647HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core…

  • CVE-2024-27124HigApr 26, 2024
    risk 0.49cvss 7.5epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build…

  • CVE-2023-39296HigJan 5, 2024
    risk 0.49cvss 7.5epss 0.02

    A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network. We have…

  • CVE-2023-39299HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music…

  • CVE-2023-32974HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the…

  • CVE-2021-34356HigOct 1, 2021
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo…

  • CVE-2021-34355HigOct 1, 2021
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo…

  • CVE-2021-34354HigOct 1, 2021
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo…

  • CVE-2021-28816HigSep 10, 2021
    risk 0.49cvss 7.6epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud,…

  • CVE-2021-28810HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.01

    If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later

  • CVE-2018-19944HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following…

  • CVE-2018-19941HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions:…

  • CVE-2018-19952HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

  • CVE-2013-6277HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.02

    QNAP VioCard 300 has hardcoded RSA private keys.

  • CVE-2018-0728HigDec 4, 2019
    risk 0.49cvss 7.5epss 0.01

    This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.

  • CVE-2018-0722HigFeb 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.

  • CVE-2018-14748HigNov 28, 2018
    risk 0.49cvss 7.5epss 0.01

    Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.

  • CVE-2018-14747HigNov 28, 2018
    risk 0.49cvss 7.5epss 0.01

    NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.

  • CVE-2017-7633HigMar 5, 2018
    risk 0.49cvss 7.5epss 0.01

    QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.

  • CVE-2017-7629HigJun 15, 2017
    risk 0.49cvss 7.5epss 0.01

    QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.

  • CVE-2015-7262HigFeb 27, 2016
    risk 0.49cvss 7.5epss 0.01

    QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in a privileged context after a reboot.

  • CVE-2015-6036HigFeb 27, 2016
    risk 0.49cvss 7.5epss 0.02

    QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a spoofed HTTP request.

  • CVE-2023-47563HigSep 6, 2024
    risk 0.48cvss 7.4epss 0.01

    An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later

  • CVE-2023-50363HigApr 26, 2024
    risk 0.48cvss 7.4epss 0.00

    An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. We have already fixed the vulnerability in the…

  • CVE-2023-47218MedFeb 13, 2024
    risk 0.48cvss 5.8epss 0.90

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build…

Page 5 of 13