Vulnerability index

Browse CVEs

171 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Qts MEDIUM 6.1
CVE-2018-0716

Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Cent…

Mitigation only
Fix from $1,600 2018-11-30
Qts CRITICAL 9.8
CVE-2018-14746

Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier…

Mitigation only
Fix from $2,300 2018-11-28
Qts CRITICAL 9.8
CVE-2018-14749

Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier v…

Mitigation only
Fix from $2,300 2018-11-28
Qts HIGH 7.5
CVE-2018-14747

NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and …

Mitigation only
Fix from $1,950 2018-11-28
Qts HIGH 7.5
CVE-2018-14748

Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and ea…

Mitigation only
Fix from $1,950 2018-11-28
Qts HIGH 7.7
CVE-2018-0721

Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and…

Mitigation only
Fix from $1,950 2018-11-27
Qts MEDIUM 5.5
CVE-2018-0719

Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Syst…

Mitigation only
Fix from $1,600 2018-11-27
Qts MEDIUM 6.1
CVE-2017-13072

Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and thei…

Mitigation only
Fix from $1,600 2018-06-21
Qts MEDIUM 6.1
CVE-2018-0711

Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote at…

Mitigation only
Fix from $1,600 2018-04-30
Qts MEDIUM 6.1
CVE-2017-7631

Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlie…

Mitigation only
Fix from $1,600 2018-03-27
Qts MEDIUM 6.1
CVE-2017-7632

Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attacke…

Mitigation only
Fix from $1,600 2018-03-27
Qts MEDIUM 5.3
CVE-2017-7630

QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware ver…

Mitigation only
Fix from $1,600 2018-03-27
Video Station CRITICAL 9.8
CVE-2017-13071

QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3…

Mitigation only
Fix from $2,300 2017-11-22
Qts CRITICAL 9.8
CVE-2017-10700

In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of …

Mitigation only
Fix from $2,300 2017-09-19
Ts 212p Firmware CRITICAL 9.8
CVE-2017-12582

Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivile…

Mitigation only
Fix from $2,300 2017-08-18
Sinage Station HIGH 7.5
CVE-2015-6036

QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a spoofed HTTP request.

Mitigation only
Fix from $1,950 2016-02-27
Viostor Network Video Recorder MEDIUM 6.8
CVE-2013-0144

Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to…

Mitigation only
Fix from $1,600 2013-06-07
Viostor Network Video Recorder MEDIUM 6.5
CVE-2013-0143EPSS 7%

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authen…

Mitigation only
Fix from $1,600 2013-06-07
Viostor Network Video Recorder MEDIUM 5.0
CVE-2013-0142

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows re…

Mitigation only
Fix from $1,600 2013-06-07
Ts 239 Pro Turbo Nas MEDIUM 5.9
CVE-2009-3200

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK …

No fix yet
Fix from $1,600 2009-09-21
Ts 239 Pro Firmware MEDIUM 5.5
CVE-2009-3278

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery …

No fix yet
Fix from $1,600 2009-09-21