Skip to content
Noroxi

qnap records

636 published records for vendor qnap.

All records

636 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • This external control of file name or path vulnerability allows remote attackers to access or modify system files.

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    qnap · photo stationDec 5, 2019

  • This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.

    CriticalCVSS 9.8KEVWeaponizedEPSS 88%

    qnap · photo stationDec 5, 2019

  • This external control of file name or path vulnerability allows remote attackers to access or modify system files.

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    qnap · photo stationDec 5, 2019

  • An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.

    CriticalCVSS 9.1KEVWeaponizedEPSS 88%

    qnap · photo stationSep 8, 2022

  • Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)

    CriticalCVSS 9.8KEVWeaponizedEPSS 78%

    qnap · hybrid backup syncMay 12, 2021

  • An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.

    HighCVSS 8.8KEVWeaponizedEPSS 73%

    qnap · qvr firmwareDec 8, 2023

  • CVE-2020-2509
    79This week

    Command Injection Vulnerability in QTS and QuTS hero

    CriticalCVSS 9.8KEVWeaponizedEPSS 34%

    qnap · qtsApr 17, 2021

  • CVE-2018-19949
    78This week

    If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.

    CriticalCVSS 9.8KEVWeaponizedEPSS 28%

    qnap · qtsOct 28, 2020

  • CVE-2019-7193
    73This week

    This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.

    CriticalCVSS 9.8KEVWeaponizedEPSS 14%

    qnap · qtsDec 5, 2019

  • CVE-2020-2506
    70This week

    improper access control vulnerability in Helpdesk

    CriticalCVSS 9.8KEVWeaponizedEPSS 2%

    qnap · helpdeskFeb 3, 2021

  • CVE-2018-19953
    63This week

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

    MediumCVSS 6.1KEVWeaponizedEPSS 29%

    qnap · qtsOct 28, 2020

  • CVE-2023-47218
    60This week

    QTS, QuTS hero, QuTScloud

    HighCVSS 8.3WeaponizedEPSS 90%

    qnap · qtsFeb 12, 2024

  • QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vect

    CriticalCVSS 9.8Proof of conceptEPSS 66%

    qnap · qtsMar 23, 2017

  • If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

    MediumCVSS 5.4KEVWeaponizedEPSS 21%

    qnap · qtsOct 28, 2020

  • QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

    CriticalCVSS 9.8Proof of conceptEPSS 57%

    qnap · qtsMar 23, 2017

  • Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access se

    HighCVSS 8.8WeaponizedEPSS 48%

    qnap · q\'centerJul 16, 2018

  • QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vector

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    qnap · qtsMar 23, 2017

  • Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated

    HighCVSS 7.2WeaponizedEPSS 59%

    qnap · q\'centerJul 16, 2018

  • A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.

    HighCVSS 8.8Proof of conceptEPSS 38%

    qnap · qtsMay 21, 2024

  • QTS, QuTS hero, QuTScloud

    CriticalCVSS 9.8No exploitEPSS 24%

    qnap · qtsMar 8, 2024

  • QTS, QuTS hero, QuTScloud

    CriticalCVSS 9.8No exploitEPSS 19%

    qnap · qtsNov 3, 2023

  • QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and

    CriticalCVSS 9.8WeaponizedEPSS 17%

    qnap · qtsSep 14, 2017

  • Missing Authentication for Critical Function in RTRR Server in HBS3

    CriticalCVSS 9.8No exploitEPSS 16%

    qnap · hybrid backup syncJul 8, 2021