Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
qnap vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2024-21900
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 buil...
Qnap Qts 5.1.3.2578
Qnap Quts Hero H5.1.3.2578
Qnap Qts
Qnap Quts Hero
Qnap Qutscloud
1 Article
8.1
CVSSv3
CVE-2021-44052
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote malicious users to traverse the file system to unintended locati...
Qnap Qts 4.2.6
Qnap Quts Hero
Qnap Qts
Qnap Qutscloud
6.1
CVSSv3
CVE-2021-44053
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote malicious users to inject malicious code. We have already fixed this vulnerability in the following versions of ...
Qnap Qts 4.2.6
Qnap Quts Hero
Qnap Qts
Qnap Qutscloud
8.8
CVSSv3
CVE-2021-44051
A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote malicious users to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, ...
Qnap Qts 4.2.6
Qnap Quts Hero
Qnap Qts
Qnap Qutscloud
6.1
CVSSv3
CVE-2021-44054
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows malicious users to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the follo...
Qnap Qts 4.2.6
Qnap Quts Hero
Qnap Qts
Qnap Qutscloud
4.8
CVSSv3
CVE-2019-7197
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an malicious user to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS ...
Qnap Qts 4.2.6
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.3.6
Qnap Qts 4.4.1
NA
CVE-2014-5457
QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
Qnap Ts-469u Firmware 4.0.7
Qnap Ts-469u -
Qnap Ts-ec1679u-rp Firmware 4.0.7
Qnap Ts-ec1679u-rp -
Qnap Ts-459u Firmware 4.0.7
Qnap Ts-459u -
Qnap Ss-839 Firmware 4.0.7
Qnap Ss-839 -
NA
CVE-2013-0142
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote malicious users to obtain web-server login access via unspecified vectors.
Qnap Viostor Network Video Recorder 4.0.3
Qnap Viostor Network Video Recorder -
Qnap Surveillance Station Pro -
Qnap Nas -
NA
CVE-2013-0143
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
Qnap Viostor Network Video Recorder 4.0.3
Qnap Viostor Network Video Recorder -
Qnap Nas -
Qnap Surveillance Station Pro -
1 EDB exploit
9.8
CVSSv3
CVE-2013-6276
QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models
Qnap Viocard-30 Firmware 2312 2.1.0
Qnap Viocard-100 Firmware -
Qnap Viocard-300 Firmware Rc B3722
Qnap Viocard-300 Firmware Rs B4631
Qnap Viogate-340a Firmware -
Qnap Viogate-340 Firmware 2308 2.1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »