qnap records
636 published records for vendor qnap.
Researcher profile
- Entered KEV
- 14 · 2.2%
- Weaponized
- 18 · 2.8%
- Pre-auth RCE
- 66
- With a fix record
- 0.3%
- Median publish → KEV
- 573 days
Recurring classes
- CWE-476 NULL Pointer Dereference83
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')74
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')58
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')57
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')46
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')45
The weakness classes this vendor ships most often: where to look.
CWEAll records
636 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
96Now | CVE-2019-7195Weaponized | This external control of file name or path vulnerability allows remote attackers to access or modify system files.qnap · photo station · CWE-22 | Critical9.8 | KEV | 89.7% | Dec 5, 2019 |
95Now | CVE-2019-7192Weaponized | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.qnap · photo station · CWE-863 | Critical9.8 | KEV | 88.1% | Dec 5, 2019 |
94Now | CVE-2019-7194Weaponized | This external control of file name or path vulnerability allows remote attackers to access or modify system files.qnap · photo station · CWE-22 | Critical9.8 | KEV | 83.1% | Dec 5, 2019 |
92Now | CVE-2022-27593Weaponized | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.qnap · photo station · CWE-610 | Critical9.1 | KEV | 87.9% | Sep 8, 2022 |
92Now | CVE-2021-28799Weaponized | Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)qnap · hybrid backup sync · CWE-285 | Critical9.8 | KEV | 78.3% | May 12, 2021 |
87Now | CVE-2023-47565Weaponized | An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.qnap · qvr firmware · CWE-78 | High8.8 | KEV | 73.3% | Dec 8, 2023 |
79This week | CVE-2020-2509Weaponized | Command Injection Vulnerability in QTS and QuTS heroqnap · qts · CWE-77 | Critical9.8 | KEV | 34.0% | Apr 17, 2021 |
78This week | CVE-2018-19949Weaponized | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.qnap · qts · CWE-20 | Critical9.8 | KEV | 28.4% | Oct 28, 2020 |
73This week | CVE-2019-7193Weaponized | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.qnap · qts · CWE-20 | Critical9.8 | KEV | 14.4% | Dec 5, 2019 |
70This week | CVE-2020-2506Weaponized | improper access control vulnerability in Helpdeskqnap · helpdesk · CWE-284 | Critical9.8 | KEV | 2.0% | Feb 3, 2021 |
63This week | CVE-2018-19953Weaponized | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.qnap · qts · CWE-79 | Medium6.1 | KEV | 28.8% | Oct 28, 2020 |
60This week | CVE-2023-47218Weaponized | QTS, QuTS hero, QuTScloudqnap · qts · CWE-77 | High8.3 | — | 89.9% | Feb 12, 2024 |
59Plan | CVE-2017-6360Proof of concept | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectqnap · qts · CWE-78 | Critical9.8 | — | 66.1% | Mar 23, 2017 |
57Plan | CVE-2018-19943Weaponized | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.qnap · qts · CWE-79 | Medium5.4 | KEV | 21.5% | Oct 28, 2020 |
56Plan | CVE-2017-6361Proof of concept | QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.qnap · qts · CWE-78 | Critical9.8 | — | 56.8% | Mar 23, 2017 |
49Plan | CVE-2018-0706Weaponized | Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access seqnap · q\'center | High8.8 | — | 48.3% | Jul 16, 2018 |
47Plan | CVE-2017-6359Proof of concept | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectorqnap · qts · CWE-78 | Critical9.8 | — | 26.9% | Mar 23, 2017 |
46Plan | CVE-2018-0707Weaponized | Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticatedqnap · q\'center · CWE-78 | High7.2 | — | 58.8% | Jul 16, 2018 |
46Plan | CVE-2024-27130Proof of concept | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-120 | High8.8 | — | 37.5% | May 21, 2024 |
46Plan | CVE-2024-21899No exploit | QTS, QuTS hero, QuTScloudqnap · qts · CWE-287 | Critical9.8 | — | 24.4% | Mar 8, 2024 |
45Plan | CVE-2023-23368No exploit | QTS, QuTS hero, QuTScloudqnap · qts · CWE-78 | Critical9.8 | — | 18.8% | Nov 3, 2023 |
44Plan | CVE-2017-13067Weaponized | QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 andqnap · qts | Critical9.8 | — | 16.7% | Sep 14, 2017 |
44Plan | CVE-2021-28809No exploit | Missing Authentication for Critical Function in RTRR Server in HBS3qnap · hybrid backup sync · CWE-284 | Critical9.8 | — | 16.1% | Jul 8, 2021 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2019-719596Now
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
CriticalCVSS 9.8KEVWeaponizedEPSS 90%qnap · photo stationDec 5, 2019
- CVE-2019-719295Now
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
CriticalCVSS 9.8KEVWeaponizedEPSS 88%qnap · photo stationDec 5, 2019
- CVE-2019-719494Now
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
CriticalCVSS 9.8KEVWeaponizedEPSS 83%qnap · photo stationDec 5, 2019
- CVE-2022-2759392Now
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.
CriticalCVSS 9.1KEVWeaponizedEPSS 88%qnap · photo stationSep 8, 2022
- CVE-2021-2879992Now
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
CriticalCVSS 9.8KEVWeaponizedEPSS 78%qnap · hybrid backup syncMay 12, 2021
- CVE-2023-4756587Now
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.
HighCVSS 8.8KEVWeaponizedEPSS 73%qnap · qvr firmwareDec 8, 2023
- CVE-2020-250979This week
Command Injection Vulnerability in QTS and QuTS hero
CriticalCVSS 9.8KEVWeaponizedEPSS 34%qnap · qtsApr 17, 2021
- CVE-2018-1994978This week
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.
CriticalCVSS 9.8KEVWeaponizedEPSS 28%qnap · qtsOct 28, 2020
- CVE-2019-719373This week
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.
CriticalCVSS 9.8KEVWeaponizedEPSS 14%qnap · qtsDec 5, 2019
- CVE-2020-250670This week
improper access control vulnerability in Helpdesk
CriticalCVSS 9.8KEVWeaponizedEPSS 2%qnap · helpdeskFeb 3, 2021
- CVE-2018-1995363This week
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
MediumCVSS 6.1KEVWeaponizedEPSS 29%qnap · qtsOct 28, 2020
- CVE-2023-4721860This week
QTS, QuTS hero, QuTScloud
HighCVSS 8.3WeaponizedEPSS 90%qnap · qtsFeb 12, 2024
- CVE-2017-636059Plan
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vect
CriticalCVSS 9.8Proof of conceptEPSS 66%qnap · qtsMar 23, 2017
- CVE-2018-1994357Plan
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
MediumCVSS 5.4KEVWeaponizedEPSS 21%qnap · qtsOct 28, 2020
- CVE-2017-636156Plan
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
CriticalCVSS 9.8Proof of conceptEPSS 57%qnap · qtsMar 23, 2017
- CVE-2018-070649Plan
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access se
HighCVSS 8.8WeaponizedEPSS 48%qnap · q\'centerJul 16, 2018
- CVE-2017-635947Plan
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vector
CriticalCVSS 9.8Proof of conceptEPSS 27%qnap · qtsMar 23, 2017
- CVE-2018-070746Plan
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated
HighCVSS 7.2WeaponizedEPSS 59%qnap · q\'centerJul 16, 2018
- CVE-2024-2713046Plan
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
HighCVSS 8.8Proof of conceptEPSS 38%qnap · qtsMay 21, 2024
- CVE-2024-2189946Plan
QTS, QuTS hero, QuTScloud
CriticalCVSS 9.8No exploitEPSS 24%qnap · qtsMar 8, 2024
- CVE-2023-2336845Plan
QTS, QuTS hero, QuTScloud
CriticalCVSS 9.8No exploitEPSS 19%qnap · qtsNov 3, 2023
- CVE-2017-1306744Plan
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and
CriticalCVSS 9.8WeaponizedEPSS 17%qnap · qtsSep 14, 2017
- CVE-2021-2880944Plan
Missing Authentication for Critical Function in RTRR Server in HBS3
CriticalCVSS 9.8No exploitEPSS 16%qnap · hybrid backup syncJul 8, 2021