Vulnerability index

Browse CVEs

539 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Music Station MEDIUM 6.1
CVE-2018-19951

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Mu…

Fix: 5.1.13 / 5.2.9+
Fix from $1,600 2020-11-02
Photo Station MEDIUM 6.1
CVE-2018-19954

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow rem…

Fix: 5.7.11 / 6.0.10+
Fix from $1,600 2020-11-02
Photo Station MEDIUM 6.1
CVE-2018-19955

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow rem…

Fix: 5.7.11 / 6.0.10+
Fix from $1,600 2020-11-02
Photo Station MEDIUM 6.1
CVE-2018-19956

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow rem…

Fix: 5.7.11 / 6.0.10+
Fix from $1,600 2020-11-02
Qts CRITICAL 9.8
CVE-2018-19949 KEVEPSS 24%

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo…

Fix: 4.2.6 / 4.3.3.1161+
Fix from $2,300 2020-10-28
Qts MEDIUM 6.1
CVE-2018-19953 KEVEPSS 24%

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the …

Fix: 4.2.6 / 4.3.3.1161+
Fix from $1,600 2020-10-28
Qts MEDIUM 5.4
CVE-2018-19943 KEVEPSS 18%

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in t…

Fix: 4.2.6 / 4.3.3.1252+
Fix from $1,600 2020-10-28
Helpdesk MEDIUM 6.5
CVE-2018-19947

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sen…

Fix: 3.0.3+
Fix from $1,600 2020-09-11
Helpdesk MEDIUM 6.5
CVE-2018-19948

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could…

Fix: 3.0.3+
Fix from $1,600 2020-09-11
Helpdesk MEDIUM 5.9
CVE-2018-19946

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could a…

Fix: 3.0.3+
Fix from $1,600 2020-09-11
Helpdesk MEDIUM 6.5
CVE-2020-2500

This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive dat…

Fix: 3.0.1+
Fix from $1,600 2020-07-01
Viocard 300 Firmware HIGH 7.5
CVE-2013-6277

QNAP VioCard 300 has hardcoded RSA private keys.

No fix yet
Fix from $1,950 2020-02-13
Qts CRITICAL 9.8
CVE-2019-7193 KEVEPSS 14%

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend…

Mitigation only
Fix from $2,300 2019-12-05
Photo Station CRITICAL 9.8
CVE-2019-7194 KEVEPSS 83%

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP rec…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Photo Station CRITICAL 9.8
CVE-2019-7195 KEVEPSS 90%

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP rec…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Qts CRITICAL 9.8
CVE-2019-7183

This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to…

Mitigation only
Fix from $2,300 2019-12-05
Photo Station CRITICAL 9.8
CVE-2019-7192 KEVEPSS 88%

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP reco…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Netbak Replicator HIGH 7.8
CVE-2019-7201

An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an aut…

Fix: after 4.5.11.816
Fix from $1,950 2019-12-04
Music Station CRITICAL 9.8
CVE-2018-0729

This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP rec…

Fix: 4.8.8 / 5.1.11+
Fix from $2,300 2019-12-04
Qts CRITICAL 9.8
CVE-2018-0730

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP reco…

Mitigation only
Fix from $2,300 2019-12-04
Helpdesk HIGH 7.5
CVE-2018-0728

This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating …

Fix: 3.0.0+
Fix from $1,950 2019-12-04
Myqnapcloud HIGH 7.5
CVE-2019-7181EPSS 10%

Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.

Fix: after 1.3.3.0925
Fix from $1,950 2019-05-09
Photo Station HIGH 7.5
CVE-2018-0722

Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.…

Fix: after 5.7.2
Fix from $1,950 2019-02-01
Q\'center Virtual Appliance MEDIUM 6.1
CVE-2018-0723

Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascrip…

Fix: after 1.8.1014
Fix from $1,600 2018-12-26
Q\'center Virtual Appliance MEDIUM 6.1
CVE-2018-0724

Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascrip…

Fix: after 1.8.1014
Fix from $1,600 2018-12-26
Qts MEDIUM 6.1
CVE-2018-0716

Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Cent…

Mitigation only
Fix from $1,600 2018-11-30
Qts CRITICAL 9.8
CVE-2018-14746

Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier…

Mitigation only
Fix from $2,300 2018-11-28
Qts CRITICAL 9.8
CVE-2018-14749

Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier v…

Mitigation only
Fix from $2,300 2018-11-28
Qts HIGH 7.5
CVE-2018-14747

NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and …

Mitigation only
Fix from $1,950 2018-11-28
Qts HIGH 7.5
CVE-2018-14748

Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and ea…

Mitigation only
Fix from $1,950 2018-11-28