Skip to main content

Vendor archive

qnap CVEs

Beta · best-effort

635 CVEs tagged to vendor qnap80 Critical, 167 High, 264 Medium, 124 Low, 0 Unrated.

CVE-2021-44053

Published May 5, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers t…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44052

Published May 5, 2022

An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this v…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44051

Published May 5, 2022

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitr…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-38693

Published May 5, 2022

A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to r…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34361

Published Feb 25, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34359

Published Feb 25, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicio…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38679

Published Feb 11, 2022

An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38678

Published Jan 14, 2022

An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redirect users to an untrusted page…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38677

Published Jan 14, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows remote attackers to inject malicious…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38674

Published Jan 7, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious c…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38688

Published Dec 29, 2021

An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38687

Published Dec 29, 2021

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary cod…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38680

Published Dec 29, 2021

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38686

Published Nov 26, 2021

An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows attackers to compromise the security of the syst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38685

Published Nov 26, 2021

A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have alr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-38681

Published Nov 20, 2021

A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to injec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34358

Published Nov 20, 2021

We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38684

Published Nov 13, 2021

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34357

Published Nov 13, 2021

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 635 CVEsPage 19 of 26