Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
qts vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2017-17032
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and previous versions could allow remote malicious users to execute arbitrary code on NAS devices.
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0387
Qnap Qts
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0358
7.5
CVSSv2
CVE-2017-17033
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and previous versions could allow remote malicious users to execute arbitrary code on NAS devices.
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0387
Qnap Qts
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0358
7.5
CVSSv2
CVE-2017-17027
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and previous versions could allow remote malicious users to execute arbitrary code on NAS devices.
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0358
Qnap Qts 4.3.4.0387
Qnap Qts
Qnap Qts 4.3.4.0372
7.5
CVSSv2
CVE-2017-17031
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and previous versions could allow remote malicious users to execute arbitrary code on NAS devices.
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0387
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0358
Qnap Qts
7.5
CVSSv2
CVE-2017-17029
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and previous versions could allow remote malicious users to execute arbitrary code on NAS devices.
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0358
Qnap Qts 4.3.4.0387
Qnap Qts 4.3.4.0370
Qnap Qts
NA
CVE-2023-23369
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1...
Qnap Qts 5.1.0.2348
Qnap Qts 4.3.6.1831
Qnap Qts 4.3.6.1750
Qnap Qts 4.3.6.1711
Qnap Qts 4.3.6.1663
Qnap Qts 4.3.6.2050
Qnap Qts 4.3.6.1965
Qnap Qts 4.3.6.1907
Qnap Qts 4.3.6.2232
Qnap Qts 4.3.6.1620
Qnap Qts 4.3.6.1446
Qnap Qts 4.3.6.1411
Qnap Qts 4.3.6.1333
Qnap Qts 4.3.6.1286
Qnap Qts 4.3.6.1263
Qnap Qts 4.3.6.1218
Qnap Qts 4.3.6.1154
Qnap Qts 4.3.6.1070
Qnap Qts 4.3.6.1033
Qnap Qts 4.3.6.1013
Qnap Qts 4.3.6.0993
Qnap Qts 4.3.6.0979
3.5
CVSSv2
CVE-2019-7197
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an malicious user to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS ...
Qnap Qts 4.2.6
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.3.6
Qnap Qts 4.4.1
4.3
CVSSv2
CVE-2018-0716
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and previous versions versions could allow remote malicious users to inject Javascript code in the compromised applicatio...
Qnap Qts 4.3.4
Qnap Qts 4.2.6
Qnap Qts 4.3.5
Qnap Qts 4.3.3
10
CVSSv2
CVE-2018-14746
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and previous versions versions could allow remote malicious users to run arbitrary commands on the NAS.
Qnap Qts 4.3.5
Qnap Qts 4.3.4
Qnap Qts 4.3.3
Qnap Qts 4.2.6
5
CVSSv2
CVE-2018-14747
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and previous versions versions could allow remote malicious users to crash the NAS media server.
Qnap Qts 4.3.5
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.2.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »