VYPR

Vendor CVEs

Qnap

All CVEs

643 total · sorted by risk
  • CVE-2024-14024MedMar 11, 2026
    risk 0.44cvss 6.7epss 0.00

    An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already…

  • CVE-2025-54154MedOct 3, 2025
    risk 0.44cvss 6.8epss 0.00

    An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version:…

  • CVE-2024-13087MedJun 6, 2025
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the…

  • CVE-2022-27600MedDec 19, 2024
    risk 0.44cvss 6.8epss 0.01

    An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the…

  • CVE-2022-27592MedSep 6, 2024
    risk 0.44cvss 6.7epss 0.00

    An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to execute unauthorized code or commands via unspecified vectors. We have already fixed the…

  • CVE-2023-47566MedFeb 2, 2024
    risk 0.44cvss 6.7epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-23370MedOct 6, 2023
    risk 0.44cvss 6.7epss 0.00

    An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified…

  • CVE-2022-27599MedSep 8, 2023
    risk 0.44cvss 6.7epss 0.00

    An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the vulnerability possibly provides local authenticated administrators with an additional, less-protected path to acquiring the information via unspecified…

  • CVE-2021-34358MedNov 20, 2021
    risk 0.44cvss 6.8epss 0.00

    We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later

  • CVE-2020-36198MedMay 13, 2021
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue…

  • CVE-2024-21903MedSep 6, 2024
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-34979MedSep 6, 2024
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-47220MedMay 3, 2024
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media…

  • CVE-2023-39302MedFeb 2, 2024
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-39294MedJan 5, 2024
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-34975MedOct 13, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the…

  • CVE-2023-32976MedOct 13, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Container Station…

  • CVE-2023-23355MedMar 29, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors. QES is not affected. We have already fixed the…

  • CVE-2018-0715MedAug 27, 2018
    risk 0.43cvss 6.1epss 0.03

    Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.

  • CVE-2026-24720MedJun 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type…

  • CVE-2026-24717MedJun 10, 2026
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the…

  • CVE-2026-22899MedJun 10, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-62858MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…

  • CVE-2026-22894MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following…

  • CVE-2025-68406MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following…

  • CVE-2025-66278MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following…

  • CVE-2025-62854MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.01

    An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following…

  • CVE-2025-62853MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following…

  • CVE-2025-58470MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following…

  • CVE-2025-58467MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the…

  • CVE-2025-57708MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type…

  • CVE-2025-54170MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (…

  • CVE-2025-54169MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5068…

  • CVE-2025-54152MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We have already fixed the vulnerability in the following…

  • CVE-2025-54148MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-54147MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-54146MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-53598MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-48722MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-47209MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-30266MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version:…

  • CVE-2025-62852MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…

  • CVE-2025-53597MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version:…

  • CVE-2025-52871MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: License Center 2.0.36 and…

  • CVE-2025-48721MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…

  • CVE-2025-53593MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…

  • CVE-2025-53592MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in…

  • CVE-2025-53591MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already…

  • CVE-2025-47208MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from…

  • CVE-2025-44013MedJan 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in…

Page 7 of 13