Skip to main content

Vendor/product archive

qnap / qts CVEs

Beta · best-effort

320 CVEs tagged to qnap / qts50 Critical, 62 High, 151 Medium, 57 Low, 0 Unrated.

CVE-2018-19944

Published Dec 31, 2020

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25847

Published Dec 29, 2020

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2498

Published Dec 10, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabili…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2497

Published Dec 10, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilitie…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2496

Published Dec 10, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the f…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2495

Published Dec 10, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the f…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2491

Published Dec 10, 2020

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-7198

Published Dec 10, 2020

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-2492

Published Nov 16, 2020

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.142…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2490

Published Nov 16, 2020

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.142…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19951

Published Nov 2, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19950

Published Nov 2, 2020

If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19953

Published Oct 28, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.…

CVSS 6.1 · Medium
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-19949

Published Oct 28, 2020

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.…

CVSS 9.8 · Critical
Buzz score
25.0
Vendor/product tagsBeta · best-effort

CVE-2018-19943

Published Oct 28, 2020

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS…

CVSS 8.0 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7195

Published Dec 5, 2019

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7194

Published Dec 5, 2019

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7193

Published Dec 5, 2019

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7192

Published Dec 5, 2019

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station t…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
45.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7185

Published Dec 5, 2019

This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnera…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7184

Published Dec 5, 2019

This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnera…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7183

Published Dec 5, 2019

This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 251-275 of 320 CVEsPage 11 of 13