Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Music Station HIGH 8.8
CVE-2020-36197EPSS 18%

An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attac…

Fix: 5.1.14 / 5.2.10+
Fix from $1,950 2021-05-13
Malware Remover MEDIUM 6.7
CVE-2020-36198

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote att…

Fix: 4.6.1.0+
Fix from $1,600 2021-05-13
Qts CRITICAL 9.8
CVE-2020-2509 KEVEPSS 33%

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.2.6 / 4.3.6+
Fix from $2,300 2021-04-17
Qts CRITICAL 9.8
CVE-2020-36195

An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulne…

Fix: 1.3.4 / 4.3.3+
Fix from $2,300 2021-04-17
Qts MEDIUM 6.1
CVE-2018-19942

A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remo…

Fix: 4.2.6 / 4.3.6+
Fix from $1,600 2021-04-16
Surveillance Station CRITICAL 9.8
CVE-2021-28797EPSS 6%

A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerabili…

Fix: 5.1.5.3.3 / 5.1.5.4.3+
Fix from $2,300 2021-04-14
Surveillance Station CRITICAL 9.8
CVE-2020-2501

A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerabili…

Fix: 5.1.5.3.3 / 5.1.5.4.3+
Fix from $2,300 2021-02-17
Photo Station MEDIUM 6.1
CVE-2020-2502

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerabil…

Fix: 6.0.11+
Fix from $1,600 2021-02-17
Helpdesk CRITICAL 9.8
CVE-2020-2506 KEV

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attacker…

Fix: 3.0.3+
Fix from $2,300 2021-02-03
Helpdesk CRITICAL 9.8
CVE-2020-2507

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attacke…

Fix: 3.0.3+
Fix from $2,300 2021-02-03
Qts HIGH 7.2
CVE-2020-2508

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.5.1.1456+
Fix from $1,950 2021-01-11
Qts CRITICAL 9.1
CVE-2018-19945

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restri…

Fix: 4.3.4.0899 / 4.3.6.0895+
Fix from $2,300 2020-12-31
Qts HIGH 7.5
CVE-2018-19941

A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in c…

Fix: 4.5.1.1456+
Fix from $1,950 2020-12-31
Qts HIGH 7.5
CVE-2018-19944

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability all…

Fix: 4.4.3.1354+
Fix from $1,950 2020-12-31
Qts HIGH 8.8
CVE-2020-25847

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…

Fix: 4.5.1.1495+
Fix from $1,950 2020-12-29
Qes HIGH 7.5
CVE-2020-2504

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues…

Fix: 2.1.1+
Fix from $1,950 2020-12-24
Qes HIGH 7.2
CVE-2020-2499

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to lo…

Fix: 2.1.1+
Fix from $1,950 2020-12-24
Qes MEDIUM 5.4
CVE-2020-2503

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already …

Fix: 2.1.1+
Fix from $1,600 2020-12-24
Quts Hero MEDIUM 6.1
CVE-2020-2498

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have a…

Fix: 4.2.6 / 4.3.3.1315+
Fix from $1,600 2020-12-10
Quts Hero CRITICAL 9.8
CVE-2019-7198

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulner…

Fix: 4.4.3.1354 / 4.5.1.1456+
Fix from $2,300 2020-12-10
Photo Station MEDIUM 6.1
CVE-2020-2491

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerabil…

Fix: 5.2.11 / 5.4.10+
Fix from $1,600 2020-12-10
Multimedia Console MEDIUM 6.1
CVE-2020-2493

This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerab…

Fix: 1.1.5+
Fix from $1,600 2020-12-10
Music Station MEDIUM 6.1
CVE-2020-2494

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability…

Fix: 5.3.12 / 5.3.13+
Fix from $1,600 2020-12-10
Quts Hero MEDIUM 6.1
CVE-2020-2495

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed …

Fix: 4.2.6 / 4.3.3.1315+
Fix from $1,600 2020-12-10
Quts Hero MEDIUM 6.1
CVE-2020-2496

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed …

Fix: 4.2.6 / 4.3.3.1315+
Fix from $1,600 2020-12-10
Quts Hero MEDIUM 6.1
CVE-2020-2497

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have alre…

Fix: 4.2.6 / 4.3.3.1315+
Fix from $1,600 2020-12-10
Qts HIGH 7.2
CVE-2020-2492

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…

Fix: 4.4.3.1421+
Fix from $1,950 2020-11-16
Qts HIGH 7.2
CVE-2020-2490

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Q…

Fix: 4.4.3.1421+
Fix from $1,950 2020-11-16
Music Station CRITICAL 9.8
CVE-2018-19950

If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. …

Fix: 5.1.13 / 5.2.9+
Fix from $2,300 2020-11-02
Music Station HIGH 7.5
CVE-2018-19952

If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. …

Fix: 5.1.13 / 5.2.9+
Fix from $1,950 2020-11-02