Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
qnap vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2017-17027
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices....
Qnap Qts
Qnap Qts 4.3.4.0358
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0387
7.5
CVSSv2
CVE-2017-17028
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices....
Qnap Qts
Qnap Qts 4.3.4.0358
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0387
7.5
CVSSv2
CVE-2017-17029
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices....
Qnap Qts
Qnap Qts 4.3.4.0358
Qnap Qts 4.3.4.0370
Qnap Qts 4.3.4.0372
Qnap Qts 4.3.4.0374
Qnap Qts 4.3.4.0387
4.3
CVSSv2
CVE-2018-0716
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application....
Qnap Qts 4.2.6
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.3.5
5
CVSSv2
CVE-2013-0142
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors....
Qnap Viostor Network Video Recorder 4.0.3
Qnap Viostor Network Video Recorder -
Qnap Surveillance Station Pro -
Qnap Nas -
7.8
CVSSv2
CVE-2018-14748
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS....
Qnap Qts 4.2.6
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.3.5
7.5
CVSSv2
CVE-2018-14749
Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS....
Qnap Qts 4.2.6
Qnap Qts 4.3.3
Qnap Qts 4.3.4
Qnap Qts 4.3.5
7.5
CVSSv2
CVE-2018-0730
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions....
Qnap Qts 4.2.6
Qnap Qts 4.3.3.0868
Qnap Qts 4.3.3.0998
Qnap Qts 4.3.4.0899
Qnap Qts 4.3.4.1029
Qnap Qts 4.3.6.0895
Qnap Qts 4.3.6.0907
Qnap Qts 4.3.6.0923
Qnap Qts 4.3.6.0944
Qnap Qts 4.3.6.0959
Qnap Qts 4.3.6.0979
Qnap Qts 4.3.6.0993
Qnap Qts 4.3.6.1013
Qnap Qts 4.3.6.1033
Qnap Qts 4.4.1.0948
Qnap Qts 4.4.1.0949
Qnap Qts 4.4.1.0978
Qnap Qts 4.4.1.0998
Qnap Qts 4.4.1.0999
Qnap Qts 4.4.1.1031
Qnap Qts 4.4.1.1033
Qnap Qts 4.4.1.1064
Qnap Qts 4.4.1.1081
Qnap Qts 4.4.1.1086
Qnap Qts 4.4.1.1101
3.5
CVSSv2
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build...
Qnap Qts
Qnap Qts 4.2.6
1 Article available
4.3
CVSSv2
CVE-2020-2497
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS...
Qnap Quts Hero
Qnap Qts
2 Articles available
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-24686
CVE-2021-21298
CVE-2021-69420
server-side request forgery
CVE-2021-23957
microsoft
SSTI
.net
SQL
CVE-2021-21273
CVE-2021-25281
1
2
3
4
5
NEXT »