Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Photo Station MEDIUM 5.4
CVE-2021-34355

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote…

Fix: 5.4.10 / 5.7.13+
Fix from $1,600 2021-10-01
Photo Station MEDIUM 5.4
CVE-2021-34356

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows rem…

Fix: 6.0.18+
Fix from $1,600 2021-10-01
Image2pdf MEDIUM 5.4
CVE-2021-38675

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this vulnerability allows remote …

Fix: 2.1.5+
Fix from $1,600 2021-10-01
Qvr CRITICAL 9.8
CVE-2021-34348

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-09-27
Qvr CRITICAL 9.8
CVE-2021-34351

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $2,300 2021-09-27
Qvr HIGH 7.2
CVE-2021-34349

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers …

Fix: 5.1.5+
Fix from $1,950 2021-09-27
Qusbcam2 CRITICAL 9.8
CVE-2021-34344

A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to …

Fix: 1.1.4+
Fix from $2,300 2021-09-10
Ej1600 Firmware CRITICAL 9.8
CVE-2021-34345

A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows …

Fix: 1.0.6+
Fix from $2,300 2021-09-10
Nvr Storage Expansion Firmware CRITICAL 9.8
CVE-2021-34346

A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows …

Fix: 1.0.6+
Fix from $2,300 2021-09-10
Qts HIGH 7.2
CVE-2021-34343

A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability all…

Fix: 4.3.3.1693 / 4.3.6.1750+
Fix from $1,950 2021-09-10
Qts HIGH 8.8
CVE-2021-28816

A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability all…

Fix: 4.3.3.1693 / 4.3.6.1750+
Fix from $1,950 2021-09-10
Qsw M2116p 2t2s Firmware HIGH 7.5
CVE-2021-28813

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch…

Fix: 1.0.6 / 1.0.6.1509+
Fix from $1,950 2021-09-10
Qts MEDIUM 6.1
CVE-2018-19957

A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnera…

Fix: 4.5.4.1715+
Fix from $1,600 2021-09-10
Viocard 30 Firmware CRITICAL 9.8
CVE-2013-6276

QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affecte…

No fix yet
Fix from $2,300 2021-08-09
Hybrid Backup Sync CRITICAL 9.8
CVE-2021-28809EPSS 16%

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack…

Fix: 3.0.210506 / 3.0.210507+
Fix from $2,300 2021-07-08
Qts CRITICAL 9.8
CVE-2021-28802

A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi…

Fix: 4.5.1.1540+
Fix from $2,300 2021-07-01
Qts CRITICAL 9.8
CVE-2021-28804

A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbi…

Fix: after 4.5.1.1540
Fix from $2,300 2021-07-01
Qts MEDIUM 6.1
CVE-2020-36194

An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject mali…

Fix: 4.5.2.1566+
Fix from $1,600 2021-07-01
Qulog Center MEDIUM 6.1
CVE-2020-36196

A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject mal…

Fix: 1.2.0+
Fix from $1,600 2021-07-01
Q\'center MEDIUM 5.4
CVE-2021-28803

This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.

Fix: 1.11.1004+
Fix from $1,600 2021-07-01
Qts CRITICAL 9.8
CVE-2021-28800

A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attack…

Fix: 4.3.3.1624 / 4.3.6.1663+
Fix from $2,300 2021-06-24
Helpdesk HIGH 8.8
CVE-2021-28814

An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise…

Fix: 3.0.4+
Fix from $1,950 2021-06-11
Qss HIGH 7.5
CVE-2021-28801

An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers …

Fix: 1.0.2+
Fix from $1,950 2021-06-11
Qss MEDIUM 5.5
CVE-2021-28805

Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability…

Fix: 1.0.3 / 1.0.12+
Fix from $1,600 2021-06-11
Roon Server HIGH 7.5
CVE-2021-28810

If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs h…

Fix: 2021-05-18+
Fix from $1,950 2021-06-08
Video Station HIGH 8.8
CVE-2021-28812

A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attac…

Fix: 5.5.4+
Fix from $1,950 2021-06-03
Qts MEDIUM 5.4
CVE-2021-28806

A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to in…

Fix: 4.5.3.1652+
Fix from $1,600 2021-06-03
Q\'center MEDIUM 5.4
CVE-2021-28807

A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remo…

Fix: 1.10.1004 / 1.12.1012+
Fix from $1,600 2021-06-03
Qts HIGH 7.5
CVE-2021-28798

A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attac…

Fix: 4.3.3.1624 / 4.3.6.1663+
Fix from $1,950 2021-05-21
Hybrid Backup Sync CRITICAL 9.8
CVE-2021-28799 KEVEPSS 78%

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability all…

Fix: 3.0.210411 / 3.0.210412+
Fix from $2,300 2021-05-13