Skip to main content

Vendor/product archive

qnap / quts_hero CVEs

Beta · best-effort

247 CVEs tagged to qnap / quts_hero12 Critical, 44 High, 133 Medium, 58 Low, 0 Unrated.

CVE-2023-23368

Published Nov 3, 2023

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-32974

Published Oct 13, 2023

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32970

Published Oct 13, 2023

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrato…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23362

Published Sep 22, 2023

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34973

Published Aug 24, 2023

An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspec…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-34972

Published Aug 24, 2023

A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network c…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-34971

Published Aug 24, 2023

An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decryp…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27598

Published Mar 29, 2023

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret val…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2022-27597

Published Mar 29, 2023

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret val…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2023-23355

Published Mar 29, 2023

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to ex…

CVSS 6.6 · Medium

CVE-2022-27596

Published Jan 30, 2023

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
28.8
Vendor/product tagsBeta · best-effort

CVE-2021-44054

Published May 5, 2022

An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44053

Published May 5, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers t…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44052

Published May 5, 2022

An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this v…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44051

Published May 5, 2022

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitr…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-38693

Published May 5, 2022

A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to r…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-38674

Published Jan 7, 2022

A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious c…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34344

Published Sep 10, 2021

A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We hav…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-34343

Published Sep 10, 2021

A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbit…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28816

Published Sep 10, 2021

A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbit…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 247 CVEsPage 9 of 10