Skip to main content

Vendor archive

qnap CVEs

Beta · best-effort

635 CVEs tagged to vendor qnap80 Critical, 167 High, 264 Medium, 124 Low, 0 Unrated.

CVE-2023-45039

Published Jan 5, 2024

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenti…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41289

Published Jan 5, 2024

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41288

Published Jan 5, 2024

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have alre…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41287

Published Jan 5, 2024

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39296

Published Jan 5, 2024

A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attr…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39294

Published Jan 5, 2024

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47565

Published Dec 8, 2023

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated u…

CVSS 8.0 · High
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-32975

Published Dec 8, 2023

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenti…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32968

Published Dec 8, 2023

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenti…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23372

Published Dec 8, 2023

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to inject maliciou…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41285

Published Nov 10, 2023

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41284

Published Nov 10, 2023

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39295

Published Nov 10, 2023

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We h…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23367

Published Nov 10, 2023

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39301

Published Nov 3, 2023

A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated us…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39299

Published Nov 3, 2023

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23368

Published Nov 3, 2023

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-23373

Published Oct 20, 2023

An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network. We have already f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34977

Published Oct 13, 2023

A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34976

Published Oct 13, 2023

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. W…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34975

Published Oct 13, 2023

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32976

Published Oct 13, 2023

An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands v…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32974

Published Oct 13, 2023

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 635 CVEsPage 17 of 26