Skip to main content

Vendor archive

qnap CVEs

Beta · best-effort

635 CVEs tagged to vendor qnap80 Critical, 167 High, 264 Medium, 124 Low, 0 Unrated.

CVE-2023-32970

Published Oct 13, 2023

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrato…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23371

Published Oct 6, 2023

A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated adm…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23370

Published Oct 6, 2023

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrator…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23366

Published Oct 6, 2023

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23365

Published Oct 6, 2023

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23364

Published Sep 22, 2023

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to exec…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23363

Published Sep 22, 2023

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execu…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23362

Published Sep 22, 2023

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27599

Published Sep 8, 2023

An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the vulnerability possibly provides local authenticated admini…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34973

Published Aug 24, 2023

An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspec…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-34972

Published Aug 24, 2023

A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network c…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-34971

Published Aug 24, 2023

An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decryp…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27598

Published Mar 29, 2023

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret val…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2022-27597

Published Mar 29, 2023

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret val…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2023-23355

Published Mar 29, 2023

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to ex…

CVSS 6.6 · Medium

CVE-2022-27596

Published Jan 30, 2023

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
28.8
Vendor/product tagsBeta · best-effort

CVE-2022-27593

Published Sep 8, 2022

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify sys…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
47.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2022-27588

Published May 5, 2022

We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2021-44057

Published May 5, 2022

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the securit…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44056

Published May 5, 2022

An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the securit…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-44055

Published May 5, 2022

An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or pe…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-44054

Published May 5, 2022

An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 426-450 of 635 CVEsPage 18 of 26