Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
qbittorrent qbittorrent vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-30801
All versions of the qBittorrent client up to and including 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default cr...
Qbittorrent Qbittorrent
9.8
CVSSv3
CVE-2019-13640
In qBittorrent prior to 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted nam...
Qbittorrent Qbittorrent
7.5
CVSSv3
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote malicious users to cause a denial of service (application crash) via an unspecified string.
Qt Qt 5.9.0
Qt Qt 5.10.0
Qt Qt 5.11.0
Qt Qt 5.12.0
Qt Qt 5.14.0
Qt Qt 5.0.1
Qt Qt 5.5.0
Qt Qt 5.7.0
Qt Qt 5.11.1
Qt Qt 5.11.3
Qt Qt 5.1.0
Qt Qt 5.2.0
Qt Qt 5.3.0
Qt Qt 5.4.0
Qt Qt 5.12.2
Qt Qt 5.12.3
Qt Qt 5.12.4
Qt Qt 5.13.0
Qt Qt 5.0.0
Qt Qt 5.6.0
Qt Qt 5.8.0
Qt Qt 5.10.1
7.1
CVSSv3
CVE-2017-12778
The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the affected flag value of the config file at the C:\Users\<username>\Roaming\qBittorrent pathname...
Qbittorrent Qbittorrent 3.3.15
6.1
CVSSv3
CVE-2017-6504
WebUI in qBittorrent prior to 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
Qbittorrent Qbittorrent
6.1
CVSSv3
CVE-2017-6503
WebUI in qBittorrent prior to 3.3.11 did not escape many values, which could potentially lead to XSS.
Qbittorrent Qbittorrent
NA
CVE-2009-1760
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent prior to 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote malicious users to create or overwrite arbitrary files via a .. (dot dot) and partial rela...
Rasterbar Software Libtorrent
Rasterbar Software Libtorrent 0.12.1
Rasterbar Software Libtorrent 0.12
Rasterbar Software Libtorrent 0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started