Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
qnap vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-14746
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and previous versions versions could allow remote malicious users to run arbitrary commands on the NAS.
Qnap Qts 4.3.5
Qnap Qts 4.3.4
Qnap Qts 4.3.3
Qnap Qts 4.2.6
7.5
CVSSv3
CVE-2018-14747
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and previous versions versions could allow remote malicious users to crash the NAS media server.
Qnap Qts 4.3.5
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.2.6
7.5
CVSSv3
CVE-2018-14748
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and previous versions versions could allow remote malicious users to power off the NAS.
Qnap Qts 4.3.3
Qnap Qts 4.2.6
Qnap Qts 4.3.5
Qnap Qts 4.3.4
6.1
CVSSv3
CVE-2018-0716
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and previous versions versions could allow remote malicious users to inject Javascript code in the compromised applicatio...
Qnap Qts 4.3.4
Qnap Qts 4.2.6
Qnap Qts 4.3.5
Qnap Qts 4.3.3
9.8
CVSSv3
CVE-2018-14749
Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and previous versions versions could have unspecified impact on the NAS.
Qnap Qts 4.3.5
Qnap Qts 4.3.4
Qnap Qts 4.3.3
Qnap Qts 4.2.6
6.1
CVSSv3
CVE-2018-19957
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote malicious users to launch privacy and security attacks. We have already fixed this vulnerability in the follow...
Qnap Qts
Qnap Quts Hero
Qnap Qutscloud
6.1
CVSSv3
CVE-2021-38674
A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote malicious users to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and Q...
Qnap Qts
Qnap Quts Hero
Qnap Qutscloud
7.2
CVSSv3
CVE-2023-32971
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the fo...
Qnap Quts Hero
Qnap Qts
Qnap Qutscloud
7.2
CVSSv3
CVE-2023-32972
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the fo...
Qnap Quts Hero
Qnap Qts
Qnap Qutscloud
7.5
CVSSv3
CVE-2018-19941
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an malicious user to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versi...
Qnap Qts
Qnap Quts Hero
Qnap Qutscloud
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »