Skip to main content

Vendor archive

qnap CVEs

Beta · best-effort

636 CVEs tagged to vendor qnap80 Critical, 167 High, 265 Medium, 124 Low, 0 Unrated.

CVE-2024-48867

Published Dec 6, 2024

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48866

Published Dec 6, 2024

An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow r…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-48865

Published Dec 6, 2024

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with loc…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48863

Published Dec 6, 2024

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48859

Published Dec 6, 2024

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compro…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50401

Published Nov 22, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50400

Published Nov 22, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50399

Published Nov 22, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50398

Published Nov 22, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50397

Published Nov 22, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50396

Published Nov 22, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50395

Published Nov 22, 2024

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network att…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48862

Published Nov 22, 2024

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended loc…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48861

Published Nov 22, 2024

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48860

Published Nov 22, 2024

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We h…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38647

Published Nov 22, 2024

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the securit…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38646

Published Nov 22, 2024

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38645

Published Nov 22, 2024

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38644

Published Nov 22, 2024

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands.…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38643

Published Nov 22, 2024

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain acce…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-37050

Published Nov 22, 2024

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37049

Published Nov 22, 2024

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37048

Published Nov 22, 2024

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37047

Published Nov 22, 2024

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37046

Published Nov 22, 2024

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained adm…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 276-300 of 636 CVEsPage 12 of 26